TFTC: A Bitcoin Podcast - Tales from the Crypt #96: Elichai Turkel
Episode Date: September 9, 2019Join Marty as he sits down with Elichai Turkel, recent Summer resident at Chaincode Labs, to discuss: - Elichai's path to cryptography and Bitcoin - Schnorr signatures - Taproot - Miniscript - Crypto...graphy - State of academic papers - much more Follow Elichai on Twitter: https://twitter.com/Elichai2 Follow Marty on Twitter: https://twitter.com/MartyBent Shoutout to this week's sponsor, Cash App. Cash App. Head over to the App Store or Google Play Store, download cash.app and start #stackingsats today. Use the promo code: "stackingsats" to receive $5 and contribute $5 to OWLS Lacrosse you download the app. Subscribe to our YouTube channel: https://www.youtube.com/channel/UCtdbWsnfA08KhSUO4amVLaQ?view_as=subscriber Contribute to the show: https://tftc.io/contribute/
Transcript
Discussion (0)
Well, hey there, freaks. It's your boy, Marty, here to introduce this week's episode with Elikai Turkle, who participated in the Chaincode Labs summer residency this summer.
Elikai is an incredibly intelligent and talented young mind in Bitcoin.
We talk a lot about Schnoor signatures, like pay-to-contract, and what you can do with sidechains, the multi-sig functionalities that will be enabled,
protecting hardware wallets and a bunch of other stuff including cryptography papers and how they're
poorly written or not poorly written just uh too heady for some some people attempting to
understand the subject this episode of tales from the crypt is brought to you by the cash app
you freaks already know all about them and if you don't let me tell you a little bit about them
the cash app is an incredible app it's the number one finance app in the app store for the last two
years probably more at this point uh and cash app allows you to do a bunch of things including buy
and sell bitcoin so you can buy bitcoin right from the cash app start stacking stats today
you can also send your bitcoin off an exchange to a private wallet straight to wasabi if you'd like
and you can also send bitcoin to the cash app now and on top of that they have an incredible
boost program where you get a personalized debit card put your signature on it a little bitcoin
sign, lightning thing, whatever you so feel. And you go to partnering merchants that are in the
boost program. You turn on the boost. For example, I went to Whole Foods, bought a few steaks over
the weekend, turned on my Whole Foods boost, saved 5% while shopping at Whole Foods. So go check out
the cash app today. And when you download it, if you haven't done so already, make sure you use the
promo code stacking sats. That's one word, stacking sats, S-T-A-C-K-I-N-G-S-A-T-S. You're
going to get five dollars and five dollars is going to go to alzacross a charity very near
and dear to our hearts here at tftc i hope you enjoyed this episode with elikai i know i had an
incredible time sitting down and talking about uh all bitcoin stuff with them so enjoy
what is up freaks welcome back to tales from the crypt it's your boy marty bent here
on a friday morning uh sitting down with a guest who i feel terrible the uh the
roundabout way he had to get here this morning mixing up the address and went to a different
part of Brooklyn, but is now here. Luckily, we called him an Uber. He's here now. We're
going to learn a lot about Schnoor, what he's been working on this summer at the Chaincode
residency, and how he got into Bitcoin. I'd like to introduce you freaks to Elokai Turkle.
Elokai, welcome to the podcast.
Thank you. Honored to be here, Marty.
I'm pumped to have you here. We met, I believe it was the first day of the residency this
summer when you guys all went to BitDevs and we went to the bar after.
I think it was it was definitely the first week maybe the second or third day but yeah it was
it was a good bit of yeah you were uh you were an inspired person when we met that night uh very
very enthused about taproot and schnor um and a bunch of other things but before we dive into
what you've been working on this summer we've been uh we've been rapping here for like the last 15
20 minutes you have a very interesting story uh you're the youngest member of the residency this
summer uh so let's talk about how you got into your very cryptography focus correct yeah yes i
love the cryptography side of bitcoin yeah so let's talk about how you got into cryptography
and then found your way to bitcoin as well um well i i started learning programming at ninth
grade and and then like i learned about this cryptography thing that you could encrypt
something that not even you can decrypt it but only the recipient which is awesome and
like signing without the ability to fake signatures and like i fell in love with the
cryptography and then i learned about a coin called bitcoin which utilizes this cryptography
to create like a whole world of how market can work and how coins were like that was crazy for
me and since then i don't think i like i never left bitcoin and uh so we're talking about this
before we hit record too you uh you sort of align with bitcoin's uh political nature and the fact
that it's a freedom enabling tool uh censorship resistant and peer-to-peer distributed why uh
why do you like these these attributes of bitcoin in particular yeah i personally believe that the
economy is too complicated to try to manipulate and control and the only way to get like close
to optimized economy is by having a free market and no one is trying to manipulate or or to force
incentives or anything just let it be and either it works the best or we'll see yeah and um
no yeah and like if not only a free market but like a free market for money where people can
call us on on a hard money that that is borderless and you're able to to trade create a metric system
for value is what uh what we've been trying to to get across here on this yeah so bitcoin takes i
think the idea of free market market a step forward like usual free markets only talk about
products but bitcoin says let's take even the coin to a free market like there shouldn't be
a controlling entity that creates coins and manipulate them and does like manual inflation
because some guy decided we need more inflation or less inflation bitcoin says like we should
have a strict rules that no one can really manipulate in a non-negligible way and everything
should be free market other than that yeah so you became enamored with uh with bitcoin pretty
quickly once you found out there was cryptography related to it and like so what happened after
you discovered it and sort of became enamored with it how did you start working in or around
bitcoin were you just in the background lurking uh building stuff or were you just like an
enthusiast for a certain amount of time yeah so i was in high school so most of the things i was
like i didn't really even have a computer i had a shitty old laptop that couldn't run almost
anything so we didn't have any gui it was like arch with nothing other than a terminal
so i built like i compiled the bitcoin core node and ran it and i tried mining but it was
too late really for mining on laptops and then for a while I got really into double spending
how does like unconfirmed double spending how does the standard rules work and how could you
use them and use miners rules to manipulate transactions and create double spends and like
I did a lot of work like around and like some tools here and there but the residency gave me
the opportunity to really dive into the cold code so what was your um so obviously you've been at
the chain code residency all summer what was your experience applying and then getting getting in
like what uh what did would you send with your with your application if you're willing to disclose
yeah so actually i also applied last year but last year they didn't have like a formal
application you just had to send an email to send an email and I literally
just sent a mute sent chain code an email saying I want to be at the
residency and that's it so they obviously ignored that email and but
this year they had like a formal application and I actually like we sent
I think the CV and some explanation of why I'm enthusiast and one thing I want
thanks Carl Dunn which I knew working on Rust Bitcoin and he's in chain code and
he helped me like to make sure that people actually look at the application
because there was hundreds of applications shout out to Carl incredible
person working on Bitcoin core everybody looking to geeks geeks you want to make
bitcoin bootstrappable and uh what's the uh what's the what's the the uh slogan he likes to
throw out there i don't remember the exact slogan but geeks is very awesome and i think it's
important to work for bitcoin yeah um and so yeah so you alluded to it there you you are drawn to
to the rust bitcoin implementation yes um i one thing that i really think could be useful
is that Rust is basically a language that is supposed to be very similar to C
and performant-wise to C,
but without the dangers of undefined behavior and memory allocations,
which I think can take a lot of the security aspects of Bitcoin a step forward.
But it's still a young language,
so we shouldn't run to change and stuff.
But I think Andrew Polstra and Carl and Matt Corallo,
are doing great work great work and related to starting to build some stuff in rust for bitcoin
which i think hopefully in the future is going to be exciting yeah so what is it particularly
about rust that that makes uh that is is attracting the uh the talent of developers
is it just easier to work with or more compact yeah i think it's mostly because it's like it's
a very ergonomic language but it doesn't have a garbage collector so you don't have the overhead
of something trying to manage the memory for you so it's an ergonomic language that doesn't have
the dangers of C with the dangling pointers and free after free and all of those stuff
but it also doesn't have a garbage collector it has it just gives you a very strict rules
of what they call lifetimes so like how long should memory live and it's all verified at
compile time so there is nothing when the program like for example in java when the program runs
there is some sort of like an engine called the garbage collector which checks if you stopped
using something and then it removes it from memory okay on the other hand in c you need to
manually allocate and deallocate by yourself that says something else they say let's have
compile time rules of how long will every object live and that's it there is nothing to allocate
to deallocate memory for you and you don't need to deallocate yourself as long as you're using
the rules correctly and they can be all verified on compile time so there is no dangerous stuff
that could happen on runtime.
Interesting.
So you're setting parameters
through which each function can run
over a certain period of time?
Right.
So like, for example, if you create,
if you allocate, let's say,
a vector of transactions inside a function,
the second the function exits,
this is automatically deallocated.
You don't need to worry about it.
Interesting.
Yeah, so it seems more efficient, if anything.
Yeah.
So in theory, and people actually did prove it,
that even though Rust should be a bit less performant than C,
Because of that, because you don't need to manually do stuff
and it might even be more performant in some use cases
and people actually showed it.
Interesting.
Yeah.
Yeah, it's fascinating.
I've talked to a lot of Matt and Carl in particular and Andrew
who are Rust developers.
Rust is something that's fairly new to me as a concept
in the last couple of years.
It's crazy how many different languages there are
and how, as an engineer, you'd have to sort of understand each of them
and the semantics within each of them, and then adapt while you're coding.
It's just something my little brain cannot handle, I don't think.
Yeah, engineers really love their programming languages, right?
Yeah.
You want to talk about toxicity.
I mean, there's some toxicity against the programming language communities, you know?
yeah like if people are talking about toxicity in bitcoin like they should see
the broader community how people can shame each other and using c-shelf or java or rust or a scale
or whatever uh no it is um it's a fact i guess somebody's been an outside observer and
i got into bitcoin via economics and finance and so that was my uh my focus of study until my
early to mid 20s and then have sort of uh tried to learn more about the the engineering and
and uh understanding the how apps and programs and software works and been fascinating learning
there's a lot there's a strong history a lot of personality and uh a lot of uh a lot of intricacies
and nuances that want us to understand like when when using an app and looking at a phone and stuff
like that and different types of technology that it's magic to most people yeah it's pretty amazing
the amount of like layers we have into everything that we use day to day and even engineers and like
we don't really know most of the like we go on a train and as even as an engineer you don't really
know how many layers are in to just making the train works and how many people are involved in
yeah and how interconnected and uh sort of dependent each system is on the other like
we're finding out in the last couple weeks we were talking about earlier the arabis attacks
which uh which can target or isps can can pull off because of their access to data and
the power that they wield uh but that's something uh in my mind at least that has not been paid
attention to like p2p network attacks um in bitcoin in particular has gotten not as much
attention as as uh say 51 attacks and stuff like that um and uh yeah we a lot of time tend to forget
that all of the new and cool stuff we have today like facebook and instagram in the end they all
rely on this very old technology like old doesn't mean bad but very like primitive gauring and all
of that like all of this can be attacked and he's being attacked all the time and like it's it's
good to remember that there's all these layers and it's not magic in the end sadly it's very
much not magic and but it does sometimes surprise me and sometimes scares me to think of uh the
percentage of your world that doesn't understand the sort of like the layering of the technology
stack that that makes our world possible today like what happens if all the engineers just leave
and go to mars yeah there's a joke of mountain engineers about the cobalt languages that that's
like an old language for mainframes yeah for banking system yeah exactly that no one is you
knowing no knows this language today and like there's be one day that there's only gonna be
one engineer that knows cobalt but all the banks are still gonna be built using that and he'll be
the only guy on earth that knows what the heck is going on it's a joke but it's true like yeah
do you know anybody learning cobalt personally no it's uh this is why we bitcoin freaks creating a
creating an alternative system to this banking system built on cobalt and easy money printing
yeah and i think it's also connecting back to geeks like why do we want to be able to control
all of the stack as much as we can and I think hopefully in the future there is
also a project called risk 5 which we could use which is open source hardware
like a geeks get us to the end of open source software that it's all
bootstrappable I think hopefully in the future even the hardware could be
bootstrappable was that serve 5 what you call risk 5 risk 5 risk yeah yeah it's
So similar to Purism, they're trying to...
Yeah, but Purism is until, like, an end.
Like, in the end, Purism still uses, as far as I know,
x86 Intel CPUs.
RISC-V is creating a new instruction set
with 100% open-source hardware,
and it's pretty promising.
How do you think we transition the world
to these types of systems?
Do you think people will want them?
Because they're harder to use now, right?
yeah so currently they're pretty hard to use and expensive but hopefully in the future
like it's gonna be a slow transition but even now people are talking about moving servers to use arm
which is the same processor we have on our phones and which also by the way the processor on our
phone and on the pc is totally different like that's arm that's x86 and yeah having a new
instruction set is hard but hopefully that could control because it's open source and bootstrappable
yeah and no it's the fact that it's open source and bootstrappable is i think something that uh
we humans are just coming to grips with right because the open source nature and the bootstrappable
nature of these systems creates these feedback loops where if you're contributing like you're
contributing to bitcoin core uh and you add value to the system and you have skin in the game in the
system you add value to yourself at the end of the day so more incentives are aligned in these
open source communities if they're if they're doing it correctly yeah and it gives us like more
understanding of all of the stack like we don't know if our incentives and for example intel's
incentives are aligned because they're doing the cpus in the end but the second it's all open source
and we can control everything end-to-end the incentives are exactly more aligned and more
like open and so was cryptography your first uh uh the first place where you dipped your toe in
the open source community um yeah i think like yeah i think bitcoin was the bitcoin and and
other cryptographic tools were the first things i've i've saw on github and used
and actually even at the start i used svn which is like the old the what was before git
and i think with bitcoin i i need i learned about git and github and started using it
so again you're the youngest resident at uh the residency this summer have you ever had like a job
by like traditional software company yeah so i worked for the past year and a half in a company
called enigma which they're actually in the ethereum ecosystem yeah i'm kidding i'm kidding
um and before that i consulted to a company for a while which called gap 600 for they're doing
insurance against bitcoin double spends but that wasn't like a traditional job it was part-time
consulting like i had one traditional job which was at enigma for a year and a half and was that
like a product manager cto uh stand-up meetings every week type of job or was it were you able
to work on like open source stuff yeah it's they're also open source yeah um like it's more
like it was less like working at microsoft and more like working on a very very small startup
yeah no that's what i'm trying to get at here like are you like yeah you're this young like
at chain code residency right now and are you do can you find yourself uh falling into like a not
even a waterfall waterfall style like a development team but even an agile team with uh with a very
a clear target where bitcoin is not as clear i mean it's clear the angle is clear but how to
get there is not as clear um and and sort of just working on this open source technology is it
is it better than working for like a company where you're being directed to what to work
on so as we've said i've never worked in an enterprise so it's hard for me to say
but yeah i personally really love the idea of open source and the like the way that
even if you work at a company
which does open source
you're more
you have more freedom than usual
enterprise because in the end it's all on
GitHub and everyone can see and comment
so it gives you more freedom
unlike enterprise
when like if the CTO or
the team leader decides something
you don't have a lot
to say in the matter
I hope to still
be in open source for the rest of my life
because I love the ideology of it
I think code should be free and open and I think it's proved itself over the years especially when
it comes to security and cryptography closed source have been broken again and again and
also open source but less severely a good example would be there's been a research paper
last year I think on the cryptography on hard drives SSDs and they found a couple of very major
companies like
Crucell and other
ones that
and even Samsung that the
encryption on the SSD was
not really
some of them weren't even encrypted at all
they just used the password as
authentication and that's it
and they were encrypting with a default
that's pretty bad yeah it is
and no one knew about it because it's all closed source
and the research paper
found it by
reverse engineering the SSDs
which I think this would have been prevented in open sourcing it,
and it probably wouldn't touch the margin of Samsung
because they shouldn't care about the code that runs on their SSD.
They're producing SSDs.
Yeah.
They should want them to be secure so they have a better product to push.
Yeah.
And if they were open source, we probably would have found it so long ago.
Well, that's the interesting thing about the particular time
that we find ourselves living in right now
because, like, cryptography,
military-grade encryption,
and open source as an ethos
for building software and things online
is so new.
Like, the internet is so new still.
And we as a species are still adapting
to this thing that is barged into our lives.
And we were talking earlier.
I was like, holy crap,
it's crazy to see how young you are
and how much you're contributing at this point.
And you were like,
you should see the kids younger than me
and what they're doing.
And, like, so I think the speed at which people can catch up to, like, the learning curve because of the access to information and the proliferation of open source in particular is helping people, like, be able to leverage this stuff faster at a younger age.
Yeah, I think we live in a very amazing era, and I'm really excited to see how all of this is going to turn up in 50, 60 years.
so how like what are what are these kids doing that are surprising you these days what was that
there was oh i actually that was that's not even new i i read yesterday about erdos he's a
mathematician and he's like he had he proved that between every number and it's square there is at
least one prime number and that was he proved that at like 20 and that was a very open problem
for a very long time and it's like there's always no matter what do you do there's always smarter
people and there's always like this crazy like people doing and you can see for example benedict
he's like so young and he just published like for the past two years so many papers like there
it's pretty awesome so many papers on what he published a paper on vrf
and he did a lot of the bulletproofs you probably heard about bulletproofs which is a zero knowledge
proof that is very cheap to do range proofs with and he together with i think andrew polstra and
peter willie they published like the bulletproofs papers and i'm not sure exactly how old is
benedict but i think he's like 2021 maybe 22 and but i don't count like i'm not sure exactly how
old easy but he's very young and like bulletproof is amazing it's i think it's crazy to see like the
age that goes lower and lower that in the past i think people were like before you're 40 like no
one cares about you yeah and today you can see very young people doing amazing stuff i mean uh
matt corral is a great example somebody got into this stuff very young as well exactly and started
contributing early and again that's i feel like the open source gives a lot of young developers
confidence too because if they ever do build up the confidence to actually try to contribute and
get feedback that happens to be good or bad it's like all right i went through this once and it
just encourages participation right yeah i hope like i really hope that we write and both open
source and in general the scientific method gives us a way to be more objective about people ages
and reputation and this gives a very good like opportunity for young people to succeed and do
a lot of awesome stuff yeah yeah so let's talk about the awesome stuff you've been working on
this summer what have you been i mean i uh i've been watching i've watched your presentation that
you gave last week at uh bit devs i'm sorry i haven't been showing up to the meetings i'm sorry
um on on schnor explaining schnor and diving into a couple concepts that i want to talk about today
in particular uh what you can do at multi-sig and then pay to contract and the things that
uh you can do like protect hardware wallets and interact with sidechains
yeah so i think that schnor is pretty amazing and it's it's time that we switch to this because
ecdsa is not the best thing yeah so um talking about the time to switch to it let's talk about
schnor's history um and why satoshi didn't pick it uh when he was originally writing the source
yeah so sadly which this actually also connects to the ideology and open source that we've been
talking about schnor published his paper even before ecdsa was standardized but he decided
to patent it i still personally don't understand how you can patent math but that's the laws and
he patented and because of this um mostly because of this ecdsa was very different than schnor even
and though Schnorr is superior in any way known.
And yeah, so because of that, there was the idea of Schnorr,
but there was no standard on how to use Schnorr
and in which way and what.
So Satoshi probably just chose the common thing
that everybody used, which was ECDSA,
because that was a standard and it was in OpenSSL.
And yeah, I think it's mostly because of the patent,
which is pretty sad.
Yeah, especially when you consider the things that Schnorr enables that you described in your presentation and now trying to figure out how to how to get it into Bitcoin is a headache we have to deal with now because of arguably because of the patent.
yeah so now that the patent has like the patent has expired in 2008 i think and now thanks to
peter willie jonas nick andrew all of the great cryptographers at blackstream and we have a very
good standard that has been highly vetted on how to use schnoll correctly and how to protect
against other attacks that could be and now that we have this standard we can start integrating
schnore into bitcoin and get like the great stuff that we that i've talked about in the presentation
and people have been talking about like pay to contract and all of those yeah so let's talk
about this great stuff like what um what excites you about about schnore so and before we can get
into what excites you like well how does it differ from ecdsa i guess it's a good place to start
Yeah, so in ECDSA, there is, like, if we, I'll try to not talk about complicated math.
Very, like, simple.
In ECDSA, you have, you need to divide the signature by something, okay?
The problem in math in general, the second you have division, it's not, it's, you can do linear stuff.
Meaning, if I have something that is, I have 5 and 8, I can easily add them up.
But if I have 5 divided by 3 and 8 divided by 2,
and these 3 and 2 are unknowns, it's very hard to add them up, okay?
So in Schnorr, there's no division, or what's called modular inversion,
which is a fancy word for division.
But so because we don't have division, we can easily add things to the signature
and remove things from the signatures and add two signatures up,
which gives us a lot of very awesome stuff that we can't do, at least not easy in ECDSA.
Yeah, and this particularly pertaining to multi-sig and enabling sort of off-chain functionalities, correct?
Yes, so in particular about multi-sig, there are ways to do multi-sig in ECDSA.
The obvious one is what we're doing in Bitcoin currently.
but that's you need to literally provide all of the public keys and all of the signatures and
verify them like one by one it's not really multi-sig in papers that are proposing to do
actual multi-sig in in ecdsa are fairly complicated and involve some of them new assumptions and with
with snore you can literally add up signatures and public keys and using the music which was
again published by peter wheelie andrew and all of their people the music gives you a way to to do it
more safely and and like have a vetted safe proven protocol that is secure to just add public keys
and signatures together and produce a multi-sig that looks exactly like pay to pub key yeah and
And this is a boon for privacy, efficiency, and again, more functionality out of the scripting, correct?
Yeah, so I think the second we use this linearity, as you said before, with off-chain stuff,
we gain a lot, both in privacy and in cost efficiency.
Because, for example, in the multi-signature scheme, you don't need to provide all of the public keys and all of the signatures.
so a you don't need to pay for them because you don't provide them b no one even knows there's
been a multi-signature it looks like pay to pub key and then it pays again and again no one knows
that there's been multiple parties so for example a very it's very easy these days to see
liquid payments for example because liquid uses a very big multi-signature i don't remember
exactly the numbers but it's very big and i don't think anyone else is uses this big of a
multi-signature. But with
Schnorr and Mucig, they look
exactly like my payments and yours.
No one would be able to know
that this is Liquid or this
is Coinbase, because they also, I
assume, have some multi-signature.
Yeah, keep going.
Yeah, so
it gives us both
privacy enhancements and
cost efficiencies.
And what type of
use cases do you see this enabling?
Or what use
cases you see this uh improving that are currently used other than multi-city yeah so now that we
if the second we have snow we could do the stuff that we've talked about like for example pay to
contract pay to contract is a way to um hide a script a bitcoin script inside of the pub key
that will only be exposed if it's used so for example let's say lightning okay in lightning
the usual transaction looks something like you pay to a two out of two multisig and to
spend this output you either have a pre-image reveal or a time lock okay all of this is visible
meaning you can see you can see that the funding transaction is paying to a two out of two and you
can see that the closing channel transaction has this complicated script but if we use pay to
contract then first of all with the music no pay to contract just music in
the funding transaction you don't see anything okay you just see pay to pub key
you don't know it's two out of two because of what we've said but then even
in the closing transaction if it's been cooperatively closed then using pay to
contract we can hide that there's been a script okay and it will look also like
pay to pub key but if it's been uncooperatively closed meaning that they
they need to actually use the pre-image or the time lock,
then they will need to reveal a script,
but we can take it, but then you expose the privacy,
and then Taproot takes it a step forward.
It says, okay, let's Merkle-ize,
let's create a tree of different scripts,
and then you just expose the correct path.
Meaning that in the Lightning scenario,
when you have both the time lock and the pre-image,
you only expose one of them.
So someone can see there has been a pre-image,
but he cannot see there has been also a time lock.
It's hidden.
So this is also pretty much increases
the amount of privacy.
Yeah, it seems like a no brainer to get implemented,
but that's the big question.
And something I'd be interested to get your thoughts on
is how do you get this like,
so Peter will propose his BIP taproot,
which includes a few of these things, not all of them, correct?
And it seems like, to me at least,
that nobody wants to step forward
and put together a signaling path or something like that.
I think there's a lot of scars from the Segwit 2X battle
from a couple of years ago
that people are sort of a little apprehensive
to even put their neck out there
to propose how we would soft fork this in.
Yeah, so I think a lot of people are still pretty scared
because of the segwit thing that we had.
I really hope that all of the community will understand
this is pretty much a no-brainer
and it will be integrated without too much of a hassle,
but still I think it's going to require a discussion
of how do we even signal?
Do we want to use the same BIP-9 as Segwit, or maybe something else?
Yeah, so let's talk about the downfalls of BIP-9.
So BIP-9 is the version BIP signaling for miners, correct?
Yes.
Where it's binary, they can signal whether or not they're ready.
They can signal if they're ready or if they're not ready,
basically using that binary bit in BIP-9.
And we found during the Segwit wars that some mining pools
were just playing with the market
and it didn't really turn out to be a great sentiment indicator, if you will.
Yeah, so I don't think anyone can really say what happened with Segwit
because it was really weird.
But yeah, we've seen that miners trying to influence the BIP9 deployments
some of them without having any valid reasoning.
just i don't want to hypothesize why because i honestly don't know it i don't think anyone knows
maybe other than the miner themselves but segwit wasn't like a very good activation and i think
people are looking in ways in other ways to activate top route without requiring the bp9
deployment what uh what would that entail do you think that's a good question i haven't looked too
much into this but one thing that can come into mind is for example the uasf user activated
software so for example users could add this to the code other other thing could be maybe in theory
signal through transactions so the transactions are going to signal instead of the miners
and then if most of the transactions are signaling this then we activate so would you have to force
transactions on people like force people to transact or um what do you mean like would the
miners be using the transactions they aggregate to signal or would individual users sending
transactions signal while they make transactions yeah so in the idea i talked about which i'm not
even sure anyone is is proposing or working on um is that yeah users will signal themselves in
the transactions but then you could argue again that miners can choose not to include these
transactions in block and that way to influence again well and that and then like think about
like the long-term hodlers who don't want to move their coins and don't want to transact like
forcing an action on them could be could be weird as well right yeah that's right um i hope there's
good proposals on how to do this i'm not sure there is a way to captures all of all of the
bitcoin users like we hopefully we would want to know what the miners opinions and what the
hodlers opinions and what the daily users and what the traders because all of them are part of bitcoin
i'm not sure there is a one way to catch them all and but honestly like this is i don't think this
requires too much like check check lock time verify got in without any discussion like i did
I don't even think I knew about the exact dates of BIP9 for that.
Like, on Segwit, I knew,
and I knew everything about the UASF and all of that,
about the check logs, log time, verify, get in without too much.
When was that?
I think either right before Segwit or right after.
I'm not really sure.
Okay.
But, yeah, I hope Taproots and Schnorr would be something similar
and we'll just get in without any community
trying to prevent it and fork in and all of that.
Yeah, just a steel man.
What would an argument against it be?
I can't think of one.
One would be complexity
because the way Bitcoin works,
we don't remove support for all stuff.
We just add and add and add.
And this incremental thing is adding complexity every time.
Even when we simplify stuff in actual code,
it adds complexity
because now we need to support the complex stuff in the past
and the simple stuff in the future instead of just the complex.
That's in general a very big problem, I think, in consensus code.
And there's been ideas of something called the big consensus cleanup
and stuff like that, like let's simplify a lot of the code,
hopefully without breaking consensus, but that's a problem with consensus.
yeah no it's a very very uh tricky problem we find ourselves in so do you uh are you partial
towards ossification as soon as possible um or are you as close to ossification as soon as possible
because obviously it will never uh get to a point where you stop stop uh tweaking it completely
um i think we should start like most of the discussions are on top right now we're being
only in mailing list what i want to do and i like other people are doing as well is trying to bring
this discussion outside of the bitcoin devs and i think your podcast is helping with that like that
the community should actually talk about it and then we can like we can know that everything is
fine and everyone like the second if only developers talk about this like it's really
hard to to sense what what's going on in the community yeah i'm going to try and talk about
as much as possible because i want this stuff i mean i think tristan and this is a huge topic
on this podcast in particular is privacy and transacting privately on the network which is
pretty hard right now it's not impossible and it's uh but it's pretty hard to to transact
privately and i think schnor just would add to the incentives to transact privately with i know you
have to have a note online at all times things like p to ep and stuff like that um and the
aggregating of signatures that is possible with schnor just just helps for overall privacy and
that is uh i think if we are going to fight the state and and uh that is an obstacle we have to
overcome in the future i think uh being able to hide from chain analysis companies is is pretty
essential yeah i think taproot and schnall together are like a very big step towards a
more private bitcoin and especially private in the sense of chain analysis companies um yeah if we
could hide most of the logic from the the public most of the logic in transactions it will be
really hard to to differentiate between stuff and this together with wasabi wallet for example
like you could open and potentially even close channels while mixing in wasabi yeah so that's
another thing you were alluding to have paid a contract so the things you can do with uh
what is it a p2sb or p2 ptsb psbt psbt that's what it is and uh hardware wallets um you were
alluding to that in your in your talk last week as well yeah so psbt is mostly a way to standardize
how do we use transactions before we send them to bit to the bitcoin network because
in the past most of the transactions were started and finished inside of core but today we have
hardware wallets we have mixed sales we have a lot of this stuff and we need to pass transactions
that are either not signed or partially signed
before we send them to the network.
And we had no standard for this.
PSBT is a way that we want to standardize this.
And it's also called partially signed Bitcoin transactions.
So that if you, for example, have a mixer
and a hardware wallet and something else,
like you could have a multi-sig with three hardware wallets,
one ledger, one trezor.
and one another company and you have the wasabi wallets as a mix cell then you need to make sure
that all of them can communicate together and it's fine which currently i don't think that's
the case and so psbt says it's a way that if we standardize this and everyone is going to use the
standard then yeah all of these wallets will be able to communicate and no matter if the
transactions contain a taproot or contain a multisig or contain a lightning funding channel
or closing channel psbt should support this and be able to do all of that yeah that's uh
it's fascinating seeing all these robust tools getting built on top of bitcoin as you were
talking about music earlier we've been talking about taproot um and now uh i always i always
getting mixed up psbt um uh and then on top of that things like miniscript that came out earlier
this week it seems like uh a lot of people especially in the all coin world are focused on
on building more robust protocols that uh that can do everything at the protocol level but it seems
like over time especially this year i feel like this year has been like a boon for tools being
built on top of bitcoin that just leverage the protocols assurances and and make it more robust
yeah i personally really believe that the trustless and fully verified nodes is like the
way to go and that's not possible with a lot of those altcoins that try to do everything
in the protocol like if you've ever tried to run an ethereum node i think we're close if not even
over the one terabyte blockchain which is gonna feel like my laptop and like it's not
it's probably like it doesn't make sense to have a fully verified node which i think is very
important to the security of bitcoin i do too and it's funny seeing uh uh other projects not
prioritize that because in my opinion it's like if you don't have that it's not worth building
these distributed systems right um so seeing have you watched eric wall tried to uh download uh
the full uh state change tracking ethereum node from scratch over the last 12 days
i didn't watch it but i tried myself in the past and it always failed at some point i never got to
have a full ethereum node end-to-end working you while you're working at enigma or um yeah and
before like i'm not i don't have anything against other technologies i'm curious to see them and
test them myself and then if i don't agree with their security assumptions and the way they do
I wouldn't use them, but I still think it's interesting to test them.
So I tried.
Didn't work out well.
What kind of hardware were you using?
Just a pretty good laptop.
Like, not some monster computer, but not something old.
Like, a very good laptop.
And it was, like, so much time, and I think it always failed,
and I had to re-index, and I tried both in Geth and in Parity,
it never really worked out i don't think i've ever gotten to run a full ethereum node
interesting now this is so what would you consider to be like your must-haves for
a cryptocurrency in terms of uh uh very small attack vectors like full nodes are obviously
um essential i would agree with you but like things like uh isp distribution too like we're
finding out with the arabis attack again like what are the areas here's a better way to phrase
the question what areas in bitcoin are most vulnerable do you think we need to work on
okay so if we're looking at bitcoin i think one of the biggest vulnerabilities are mining pools
which matt corallo is doing very great job with better hash to to prevent that because currently
there is very little security
in the pools and you could steal
a hashing power
and like
if you're an ISP for example in
China where most of the mining actually
happens you could steal a lot of the
mining power and to manipulate
Bitcoin while the incentives
of Bitcoin doesn't protect us
against that because you don't have any skin
in the game you're literally stealing
the mining power
which is I think a very big vulnerability
Yeah, no, I would agree.
So things like BetterHash, which allow individual miners to construct their own block templates,
would, even if the ISP did have control of that physically located mining pool,
they would not be able to dictate the block template and which transactions are included in those blocks, correct?
Yes, BetterHash gives you the ability both for individual miners, as you said,
to create their own templates
and I think some optional encryption
and authentication,
at least authentication
with the pool that they know
that what they got is actually from the pool
and not from some man in the middle
and a lot of cool stuff
that would hopefully make
the mining pools more robust.
And what would you consider
like a acceptable number of full nodes
running in the world?
Like do you think 10,000 is enough right now?
I don't think exact numbers are the way to measure it.
I would hope that we have in the end
between five to 10% of users running full nodes.
I think more than that, like in a,
I'm talking about like a world where everyone uses Bitcoin.
I don't think my grandmother should ever run a full node.
I don't think it's reasonable, but I do hope that,
I do think that 5% to 10% of the users should have full nodes.
Yeah.
So do you see a future in which there's a Bitcoin expert in the family
who runs the nodes and you can connect through the family node if you must,
but there will always be that family enthusiast who contributes to the consensus?
I actually never thought of that, but in theory, yes.
Today, I think every family has the one guy that actually knows
how computers kind of work and helps everyone with their phone problems so potentially he would
have a full node and the family would connect to that yeah that's interesting i can get down with
that future yeah and and i think that's even better than what i imagine like with that you
literally trust only your family relative with a which i think like with most families at least
it's pretty good trust yeah it should be at least i hope so i hope you can trust
trust your family out there i do yeah i hope so um no it's it's it's gonna be fat and that's the
that's the beauty of bitcoin right now why i think it's so exciting to be a part of it because we
truly do not know how all this is going to unravel and the tendencies and the use cases that are
going to be enabled and how people are going to interact with it but it is fun to uh to wax poetic
and think about a future where family members
are running full nodes
for other family members to connect to.
Yeah, and I think what's interesting is that
not all of the community needs to agree
on what the correct future,
and we can see it, for example, in Electrum.
Electrum is running their own different network protocol
with different security assumptions
for SPV or light wallets,
and some people are fine with it,
and we'll see in the future
what's the best suitable for different kinds of people
and we cannot control the future.
I think that's good.
Yeah.
No, and also the fact that we don't know the future
creates this opportunity to build a future
that we see fit for ourselves.
And again, Bitcoin's been this organic self-organizing system
between developers, miners, holders, you name it.
There's people organically coming together
around this protocol.
Over the last decade and that's that's the other thing like so how long do you see Bitcoin persisting into the future?
Do you see it as a system? That's around like millennia a couple centuries a couple decades
That's a hard question
I would say
Bitcoin as we know it I
Would give it a maximum of a few more decades
because
Like, looking at the history of cryptography, for example,
discrete logs are going to break.
Like, I don't think any, like, cryptographic assumption
was ever consisted more than a few hundred years.
And quantum computers are doing some, like, interesting developments.
Not for any time soon, but, yeah,
but maybe bitcoin would be able to adapt with like evolution and it's still gonna be bitcoin
even in 200 years it's gonna be looking a bit different than today's but it might still be
bitcoin i don't know yeah no it's uh that's actually one of my favorite themes to follow
on bitcoin is bitcoin as a living organism like ralph merkle talking about it replicating itself
and stuff like that and then people like brandon quittem is who's written about bitcoin as a is a
slime mold like a self-organizing system akin to slime mold fungi um and and many others have
written about uh bitcoin as a living organism and it does adapt and it's it's because we're
part of it right we're building it yeah i think it's part of the open source idea that there is
not a single entity that controls the code and it evolves over time and and even like even people
that do criticize that in the end it's only a handful of people like approving merges into
github look today and five years ago they were totally different people like that's the the
exciting thing about open source today there is only handful of people but five years from now
it's totally different handful of people yeah it's like uh it's like human bodies like our blood
cells regenerate and die and we don't have the same blood cells in our body that we did 10 years
ago but we're the same person right yeah exactly we don't need more and more blood cells we just
need them replaced yeah i'm getting heady here we haven't even we haven't even ripped out the
the herbal enhancements uh for this one but um no i was uh i was stalking your twitter account
and uh i saw that you're yelling at somebody for for uh uh for um excuse me that's the word i'm
looking for here i'm losing my words today somebody for um
you yelled at somebody for recommending voting on blockchains why can't we vote on blockchains
their their finality their finality uh or their uh close to finality should be
an assurance for voting systems right so i'll give you an example in the the guy i don't remember
his name but the guy who invented the laser said that the laser is a solution looking for a problem
okay but today we found problems that laser solves and it solves them great but that's not
usually especially when it comes to actually people because lasers was like a physics invention
it didn't involve like affecting people life we shouldn't force solutions on top of problems
okay voting is a very known problem that's been around for centuries and there's tons of research
into it and it's a very very nuanced problem meaning as you said finality is something very
wanted when it comes to voting but it's hardly the only thing that you want in voting you want
finality you want privacy you want something very different than what's what we call privacy
Because in voting, you want to be able to vote only once without anyone knowing what you voted for, but without you being able to prove what you voted for, which usual encryption doesn't give you, because the usual encryption lets you prove what you voted for, which is a problem, because if you can prove who you voted for, you can be bribed.
okay so voting is a very very nuanced subject with tons of research into and tons of different
solutions some of them cryptographic and some of them very like old and primitive and these are
great we shouldn't force this new cool thing called blockchain on top of it which personally
i've didn't i didn't see a single blockchain solution that actually covers all of the nuances
in voting yeah it's uh even like electric voting is something that we can't figure out like to
think that we're gonna form fit a blockchain solution on top of this centuries-old problem
like you said is a bit naive to me and i guess that's another good topic to get into like
what is a good use case for a blockchain in your opinion um is it only imperative for monetary
goods in the digital age or their extensions of blockchains use cases that that we'll we'll see
in the future yeah i think the exciting thing is to say i don't know but again we shouldn't
force anything we should wait and see and we should have real discussions like
there's a tendency for people not even in blockchain in general when they have this
new shiny thing they want to use it everywhere then they can even when it's not reasonable okay
blockchains today are very very inefficient okay as databases and as consensus mechanisms even like
consensus is also satoshi didn't invent consensus consensus was talked about for since the
byzantine problem and and the byzantine problem is the only is that is one of the first ones to
actually stand like standardizes what is the consensus problem but that's been talked about
again for more than decades there's different solutions for in every consensus solution is
appropriate for this for a specific problem i think the block what we call blockchain is a
very good solution for money i'm not sure what other stuff it's good solution to probably there
our other stuff but not as much as we think yeah no it's actually one of my favorite people to have
this conversation with is james o'byrne from chaincode and uh he does a very good job of
explaining via negativa like why blockchains probably only make sense for a few use cases but
no that it does look like especially after 2017 2016 2017 with the ico craze of everybody trying
to take blockchain and form-fit it
on every advertising, medical,
and travel company in the world.
I think we learned some hard lessons in that
as evidenced by the lack of products
that have been brought to market.
Yeah, and we need to remember
that even the simplest requirement
for a lot of use cases called privacy
is not simple and is very nuanced.
Even the fact that you've been to the doctor
might be something you don't want to disclose and even in a future fully encrypted blockchain
fully homomorphic blockchain that no one can knows what happens you probably can still at least as we
see it today like correlate a person doing something and this might be for the medical
use case still bad so like even the word privacy doesn't mean one single thing and it's very
different per use case yeah no as as you use bitcoin you find that out pretty quickly like
you can blow your privacy simply by going to a block explorer and looking up an address or
not using a vpn when you're sending it out there's many ways you could be on an isp that
is spying on you and stuff like that um it's uh it's an intricate hard problem to solve uh
but you have to get back to work here soon uh let's wrap it up with a few questions i was also
stalking your twitter and saw that you're very angry with the state of cryptography papers and
how hard they are to read what is going on yeah so there's this is something that is more like
close to my heart i'm not an academic i've never been to academia i have no degree
but i'm really interested in cryptography and a lot of number theory stuff which is a very there's
a big barrier i don't know if it's on purpose or not but a lot of papers and and and even lectures
online like there's a they don't explain the symbols they use they don't explain a lot of
they don't give definitions to to ideas and it's really hard for someone outside of the academia
to read those papers and actually understand them and i want to give a shout out to djb daniel j
berenstein which a has a lot of great work b i think the way he writes papers and i'm sure others
also do this but a lot the way he writes is he usually gives appendixes and and definitions to
almost everything so that when you come to a paper you can come like like almost from scratch
almost saying like you still need to know algebra and you still need to know something
but when you see the sigma symbol he usually gives at least in words an explanation of what
does it mean when he just says a finite field he doesn't just say finite field he gives an
appendix explaining what is a finite field which i think is very welcome to like to bridge the gap
between the academia and the rest of the world, because algebra might look very
frightening, but it's honestly not. But, like, there is a very big bridge you
need to cross that even today, for me, it's hard to cross sometimes.
I can read a paper and, like, need to look up every single thing,
and a lot of this stuff you can't even find on Google.
So the good thing is we have ILC and people that love to give you answers.
But yeah, that's sad.
I would love to see papers more self-explanatory.
Do you ever have urges to go through the academic process and learn?
Or do you think that's a waste of time?
Yeah, I'm still thinking of that.
It's hard to make a good decision because I honestly don't know too much
because I've never been in the academia
of how and why and what.
We'll see.
I wish you well on that journey
to figure out whether or not
you want to go on to academia or not.
Thank you.
I hope you can avoid it
because I think you're doing a good job
without it at this point.
I guess, what do you do outside of Bitcoin?
What interests you
when you're not thinking about cryptography
and how it applies to Bitcoin?
Mostly I think about Bitcoin and cryptography.
yeah i'm the same way is there any uh any parting notes or words of wisdom you want to imbue on the
freaks out there um don't be afraid i think like a lot of things are looks very scary on the outside
but they're not that scary like neither does bitcoin cold code nor cryptography and a lot
of other stuff don't be afraid some good words of wisdom jump into the fray uh that's all we
got for this week, freaks. Peace and love.
