{
  "episodeId": "SLP100",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "pavol_rusnak_stick": {
      "name": "Pavol Rusnak (Stick)",
      "role": "guest",
      "tag": "PAVOL"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.63,
      "text": "Hi and welcome to the Stephan Livera podcast focused on Bitcoin and Austrian economics. Today it is episode one hundred with Pavol Rusnak. But first, before we carry on with the hardware wallet interview series, let me introduce the sponsors of the podcast. So firstly, look into Kraken, one of the top Bitcoin exchanges. They have an incredible focus on security. They've got Kraken Security Labs, which is working not just on the security of Kraken itself, but of other participants in the cryptocurrency world. They're known for acting ethically in the space, they're one of the longest standing Bitcoin exchanges, they're consistently rated the best, and if you're trading in- They need to be somewhere with some of the best liquidity in the industry. They've got high trading volume and low fees, no minimum or hidden fees. Kraken have twenty four seven support, and on the institutional and business solution side, they're very popular with institutions. They're providing the best in class accounting, reconciliation, and reporting services for cryptocurrency hedge funds, asset managers, and fund administrators. Don't forget, there's a Kraken OTC desk for those higher touch block trades. They offer five fiat currencies, and they've also got margin and futures trading. So to- Learn more and sign up, go to the Kraken link in the show notes. Next up is Unchained Capital, these guys are doing Bitcoin financial services and they've got a two of three keys multi-signature vault. So there's a bit of focus around security, you can use Trezor or Ledger wallets and you still maintain control because you still have two of the three keys, reducing that single point of failure risk and also if somebody were to attack you, they would need to take you to where your other key is as well, so it gives you a bit of buffer there. So if you create And Unchained Vault, you also get three free months of access to SafetyNetum's Bitcoin Standard Research Bulletin. And Unchained also offer Bitcoin collateralized loans, allowing you to get USD liquidity without selling your bitcoins, and it also means you don't trigger a capital gains tax event. So while that loan's outstanding, it's stored in what's called collaborative custody with Unchained holding one of three keys, you hold a second key, and Unchained's independent third party key agent holds the third key. To learn more and sign up, go to the The Unchained Capital link in the show notes. So today we are carrying on with the hardware wallet interview series. I hope you guys are really enjoying the interviews so far. I think they've been quite educational and a good place for a newbie to get some info. So today we are interviewing Pavol, also known as Stick, he is the CTO of Satoshi Labs, the company behind Trezor. So with Pavol, we talk about making the world's first Bitcoin hardware wallet, we talk about multisig, which is that's also quite interesting today. these days, we talk about PSBT and airgapping with an SD card, we talk about the privacy implications and how that will change with the coming Trezor Suite, and also I'm quite excited about this coming idea of Bitcoin only firmware for the Trezor. So with that, onto the interview. Pavol, welcome to the show. Hello, hello. So, look, thanks for joining me in the hardware wallet interview series, and obviously, I, you know, had to get someone from Trezor on, so it was great to have you to join me. let's, let's start with a little bit on the background on you. let's hear a little bit on, you know, how you got into Bitcoin and a little bit of your history with Satoshi Labs."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "03:31",
      "start": 211.24,
      "text": "Yeah, alright. So, I was born in Slovakia, but, since 201 to two thousand two, I am living in Prague. I moved there to study computer science at Charles University. And even during the studies, I already started to work at a company called SUSE Linux, which is, one of the biggest commercial, Linux, Linux vendors. And that got me into the world of open source because everything we did back then, was open source, and I was collaborating a lot with, With people not only inside of our company, but also with the competitors like Red Hat, but we got our own common goal to be, a good, Linux ecosystem basically, and During the, that time, I think it was like two thousand twelve or even, a little bit before that, we started, a hackerspace in Prague called Bermlab. And, somehow, there was, a conference, in two thousand eleven called Bitcoin Conference, organized by Amir Taki. And he came to the hackerspace telling us about bitcoins and how we should attend the conference. And it was pretty nice and That's where I think maybe not for the first time, but maybe for the first time I met Slash, and we were discussing a lot about, hardware aspects of, of Bitcoin. And basically it was mostly about mining, but then we were also, talking about the security of the, of the coins, and that is a, is a, is a basically it's a huge problem to have private keys stored on your computer. And coincidentally, there was a talk at the, the- That particular two thousand eleven conference by Clemens Kap, it, he was a German professor and he was presenting his, and h-idea of his students, of a hardware wallet, and they were building that on Arduino, and we had a lot of discussion with Slash that it's probably not, enough power because it would take like maybe one or two minutes to sign a transaction, and that's not very usable, and, we played with the Idea a little bit, but not very much, because I still, was working, at, at my previous company, and Slash was very busy with his, Slashpool back then. And, one year later, in 2012, there was a Bitcoin conference in London, and there was absolutely no mention of any hardware wallet effort, and that was the tipping point where we basically decided we should start, do Doing this because nobody is, taking care of that really, crucial and missing part of the ecosystem. And we started to think a little bit at the Berlin Lab Hackspace and playing with the ideas how it should, how it should work and, be-- both me and Slash, we were software engineers, we basically had really no idea what we were doing at the time, but it was fun and we, learned a lot. And, some, somehow the ecosystem also changed, and from the original idea where we wanted to produce like, one hundred devices for our friends and from the people we knew from the Bitcoin Talk, the ecosystem got bigger, and, it was, in 2013 when Alana, joined us and persuaded us basically that we should really start a company and, Do that in a really big batch, so that was how, Satoshi Labs and Trezor was started. In two thousand and thirteen, there was an official company started back then."
    },
    {
      "speaker": "stephan",
      "time": "07:28",
      "start": 447.79,
      "text": "Yeah, so look, it's obviously this is the world's first Bitcoin hardware wallet. What were some of the challenges and the trials that you faced along the way when you were building that first device, the Trezor One?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "07:42",
      "start": 461.74,
      "text": "Like, like I mentioned, we had really no, very good idea what we were doing back then. At a time. funnily enough, Trezor was my first, PCB ever created, and it seems it somehow worked fine. Obviously, there were a lot of, other iterations, later. And what-- in the beginning, what seemed to be the biggest problem, it turned out to be really easy. I mean, the electronics and something that we have never thought might be a problem turned out to be a big problem. So, we- We had the electronics ready in maybe two thousand thirteen, but then we had a really huge problem with, getting these electronics into either a metal casing or plastic casing, which, was kind of crucial because we wanted to deliver, a full product, not just the electronics board. And with the metal casing, we had the problem that the buttons were just too small, and at one point, during the process, you need to put this This aluminum parts into an acid basically to create this protective coating on top, and that's a very delicate process because if you don't, have, this aluminum in acid for a long time, the protective, coat will not, get created, but if you keep that there for a long time, the acid will start to dissolve the parts a little bit. And the problem with- Buttons was, they were just too small, so, if we kept them in acid for like a minute, the protective, layer wasn't there yet, but if it was like one minute and fifteen seconds, the buttons were just completely dissolved suddenly. So there was a really, really delicate timing, and finally we were able to figure it out. And, moved on to creating, a mold for injection molding, and this turned out to be also a really big, a really big problem because of, of again the small, small buttons and, some other, other areas. Which, in, in reality, we had to postpone the launch of the plastic version for a couple of months, maybe half a year even. So,"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "10:07",
      "start": 607.37,
      "text": "This just never worked out with the original producer, and finally, it was late two thousand, or it was, I think it was like middle two thousand and fourteen, we were able to find a company, in the Czech Republic which was able to produce both electronics and both, plastic cases for, for Trezor, and we have this relationship since back then, and, it's really, really healthy relationship. Because they, they can guarantee the electronics will fit into the plastics and, that's how we resolved the problem basically to, to find a good partner to help, this with us. another problem, which turned out to be, unexpected a little bit was, the original idea is that we will produce just the hardware and the software wallet ecosystems, will integrate the Trezor, but, there were Very, there were different priorities for, for the software, software wallet developers, so it turned out that we need to come up with our own, web wallet so our users can actually use Trezor. luckily, some time later, all the software wallets started integrating, Trezor. One of the best integrations now is available on Electrum, and we are happy about that because we- Want to be a part of the ecosystem, we don't want to, we don't want to tell people how to use Trezor. So I'm really happy that there are other options. And this was the original idea, but, for a couple of years it wasn't possible. Yeah. So this, these two were the biggest challenges, manufacturing problem and the integration of Trezor into other parts of ecosystem."
    },
    {
      "speaker": "stephan",
      "time": "12:03",
      "start": 722.73,
      "text": "Yeah, that's fascinating to hear from your point of view. I think from my point of view, it's, for a long time, it's been my typical recommendation for newbies that, you know, if you're a newbie and you need to get your coins off the exchange, I would normally tell them, \"Hey, just get a Trezor. It's one of the well-known kind of, products that, you can give to a newbie and that that person can pretty much just plug it in and it's mostly a nice web wallet interface for them.\" although obviously But we might get to that later, but I think on the whole, it should be recognized that, you know, this is the first Bitcoin wallet and it's, you know, to this day, better than people leaving it on an exchange, right? but, let's talk through some of the features then of the, the Trezor, 'cause you've got two main products, right? This is the Trezor One and then the Trezor Model T. So, do you wanna just talk through, just at a high level, what are some of the main"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "13:01",
      "start": 781.19,
      "text": "And it's also being used as a ben- benchmark for any, any other upcoming wallet, and people are selling, saying like, \"Oh yeah, this is, this feature is better than Trezor has, or this feature is worse than Trezor has.\" And, the original idea was just very easy. We just, want to have, buttons and a display, the display being the crucial part because we wanted to, we wanted to give a, give a full verification. available to user, so they could, check not only the amounts they are sending, but also where, the coins are being sent to. And, this, this original design is very simplistic, it's minimalistic, it's very durable, even though it's made from plastic, but, that has another advantage, is very, it's very light. So if you drop it for, I don't know, five meters, it will survive because, it's, even if, if it- Even if it's made of plastic, it, it will survive such fall. And we plan to keep selling them because they are, like you said, they are the go-to solution for, for, for people, and we still think it's a, it's a very good product, Another model, like you said, is the Model T. It was released in February last year, 2018, and, it's, it's an evolution of the idea, where we replace the- Monochromatic means black and white, display with, colorful high-res display, and we replace the buttons with the touchscreen. it provides, much better user experience for people that need to use, Trezor every day or if you want to perform like more complex operations, if you are sending, coins in one transaction to multiple people, it's, much easier to check the correctness of the transaction on a, on a bigger display. And, we, we consider that, a-as, as like a flagship of our, products, and Trezor Model T is, is, oh, sorry, Trezor One is, it's like the entry, entry le-level. That said, most of the core, features, that means like management or, Bitcoin-related features, are also available on Trezor, Trezor One. So, if you don't care about expert features, Trezor- Trezeor One is perfect for, for you. also Model T, has, SD card, which allows us to perform, some of the actions that aren't just not possible on Trezeor One. We might get, up to that, later, but one of these is basically we can perform, bootloader upgrade or firmware upgrade via SD card. So, if the device is bricked for whatever reason or, if you just don't want To connect the device to the computer to perform the update, you could, do that via, via SD card."
    },
    {
      "speaker": "stephan",
      "time": "16:11",
      "start": 970.74,
      "text": "Great. So let's start with multi-signature. So I know that's, that's something that is, the focus is coming onto that a little bit now, and there's a little bit more desire for multi-signature. I know currently it is possible to do with Electrum, that you can multi-run a multi-sig out out of that and use Trezor devices as part of your multisig set. I know also that, the Trezor has Basically, it displays some additional details about that transaction when you're performing the multi-signature. So, did you wanna just outline some of the thoughts around that?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "16:54",
      "start": 1013.62,
      "text": "Yeah. it's funny to say, la-- it's funny to hear, Ludovic, say that the multi-sig is, getting traction now, because that's obviously true, but also it was getting traction back in, two thousand fifteen. So there are not only the hype cycles for, for the price of the Bitcoin, but also for- For various features. And, back in two thousand fifteen, we were discussing how to introduce the multisig, in Trezor and, we were spending a lot of time with trying to come up with great user experience, and we discussed how these multisig parties should be coordinated together, and we were experimenting with, all of crazy synchronizing mechanisms via, via Jabber or WebRTC. So, you could, synchronize these parties over, over the browser, but then we realized we are basically inventing like, or like, it seemed to us like we are in-ta-inventing the whole new internet, so we kind of postponed that, features and decided just to, finish the multisig implementation inside of the device and, see how the feature evolves. And it's nice to see that now there is another- Other traction and basically we have all these multisig features in the hardware wallets and now we are trying to figure out how to make this user experience, worthwhile for users. And one of the problems we had, back then in 2015 was that, There was not a very easy way how to prove that the multisig address is indeed being used. so if, if a software wallet shows you, \"Alright, so this is the multisig address, you can use it,\" but still you don't have a proof, that the connected device is indeed, is indeed, involved in that multisig scheme. so we came up with a mechanism that can, basically, a software wallet can tell, the device, please show me this, this address, this multisig address, and there is a proof that you are indeed involved in that multisig setup, and, the hardware wallet or Trezor in that case will look at this proof, and only if, it is able to reconstruct that proof, it will show the multisig address on, on the display. So that way you can Be really sure that the software wallet, that the address you see in the software wallet, and at the same time if you see the address on, on, on Trezor, you can be sure that particular Trezor is indeed involved in that, multisig scheme. this can be done best, in an electrom, if you have a multisig setup, backed, via Trezor. There, is an eye icon, next to the address, and if you have a free Trezor's Connected, there will be three i icons next to the address, and you can just press, first, second, or third, and it will show you the multisig, multisig, address on, on the particular device so you can check, and re-really be sure that this Trezor wasn't omitted from the scheme and it's indeed being used."
    },
    {
      "speaker": "stephan",
      "time": "20:25",
      "start": 1225.21,
      "text": "Fantastic. And yeah, so that's actually something I've recently tested out as well with, Electrum as well. I just wanted to make sure that part of it as well, that you, you really can see it, so when you click the eye in Electrum, and then it shows on your hardware device that's plugged in. although, yeah, so and then the other component with multi-signature is also now the idea and this concept of, well, we wanna try to, in some sense, make it more difficult for an attacker, and one way to do that is Signature with the same manufacturer, but multisig with other device types. So can you talk to a little, can you talk to us a little bit on setting up a multisig with different hard, hardware wallets? Sure."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "21:09",
      "start": 1268.56,
      "text": "So, if you want to use different hardware wallets, and I think it's a good idea because then you are reducing, reducing the, the fragility of, of the setup basically. you need to find a solution that communicates with, the hardware devices of different vendors. And one of these, is, Electrum, like we mentioned earlier. There is a really good blog post by, Salim Rashid on his, On his blog where he describes, experience, and, individual steps how to configure that. But actually, it's, pretty straightforward. there is, there is a, there is a guide in Electrum. So if you just choose, I want to use multisig, I want to use a hardware back multi-multisig, and then, it will try to look for the devices and you will just pick the devices, f- the, from, from the detected list and it can create a scheme, for that. there are also, companies, for example, Casa, they are trying to make this process even, even more, straightforward for people, and they also support, different, hardware vendors, and they also have some, enterprise, schemes, or maybe not enterprise, but aimed for common users, but they- There are commercial schemes where, you can have, Casa participating as, as one of the multisig parties, so in case something, goes wrong, you can use their, their servers to recover the situation."
    },
    {
      "speaker": "stephan",
      "time": "22:55",
      "start": 1375.17,
      "text": "Great. let's talk now about, another concept is around backing up and the seed. And so related to that is this idea of Shamir's secret sharing. And so I know with, Trezor, there is this slip thirty-nine. Can you tell us a little bit about that? Sure, sure."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "23:14",
      "start": 1394.5,
      "text": "So, the original, standard for mnemonic seeds, was called, or is still called BIP39, and we came up with the, with the definition in 2013. it wasn't an original idea. There were some other implementations predating that. one of them was Electrum, Electrum, but it was never standardized, and we really felt that we need to put, put there a standard Standard so other hardware and software wallets can, implement that, and that way we could achieve interoperability of the seed. I'm really happy to say that now every hardware and even every single software wallet, supports B39, so, you can exchange these mnemonic backups, as you wish, like if, if your hardware wallet breaks down, you can buy another one. Or even from another vendor or, or use the software wallet if, if you, if you want to recover that. And, we, we thought we, it would be great to came up with another standard, again, an open standard so everybody can implement this, and we hope we will achieve interoperability of that, with, Shamir secret, sharing scheme. And the idea is, actually very simple, right? Right now, if you initialize the Trezor, it will give you a set of words. They can be either twelve or twenty-four words, and you can use this mnemonic sentence to recover your device. Shamir secret sharing scheme is a so-called threshold secret sharing scheme, so it will, it will give you, for example, five, sentences. They are twenty words long, and during the initializ-initialization, you would just say, \"Alright, so these are the...\" These five sentences, but it is okay to provide just three of them to fully recover the secret. there is one big advantage of, on- just splitting the old seed. If you have a B-39 seed and you split that, in half, there is an issue, if, if, if somebody has half of your seed, then they can still, recover half of the secret. But the Shamir, scheme doesn't work that way. Like if you don't have enough, shares, if you are under the threshold, you can't recover anything, and that's a really big advantage, and I think- the, this, this is the scheme that should be really used in case you want to have a function like that and not to split, the old, old seed, by some common, some custom scheme."
    },
    {
      "speaker": "stephan",
      "time": "26:09",
      "start": 1569.21,
      "text": "so let me just clarify that. So as I understand that, this is the twelve or twenty-four word seed, and what some people have been doing, which is not the recommended practice, is to actually split that twenty-four word seed up and say, \"Oh, I'll put half here and half there,\" but that obviously puts them- At a greater risk, let's say if a, if an attacker gets one of those halves, now it's easier for them to try and brute force you or to try and, you know, figure out, you know, what your- The address. Yeah. Yeah. And so this method, you're saying to use Shamir's secret sharing, you can split that in a way that, say, those twenty-four words, you can split that in a more clever way, right? And so make it so that even if they got two of five in that example They would not be able to recover your seed, correct?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "26:57",
      "start": 1616.95,
      "text": "Exactly. I-if I during the initialisation say, \"You need three out of five, you need three out of five, nothing, nothing less won't work,\" they wouldn't recover any, any, even partially secret. So, there is also an advanced version of, Shamir also described in the paper, and it's, it's, like a second, second level of Shamir where we intro- we, we introduce groups. So you could, instruct Trezor to generate, two groups of seeds, and each group, will, again have its threshold. So, let me give an example. I have a group of family members, and I will say, alright, so, we need three out of five of these family shares. Then I have a group of coworkers, and I would say, okay, we need four out of six of these coworker shares, and then I need two out of two of this group shares combined. So, so that, that way I can create like a really complex setup, depending on who do I trust and who I don't trust. one of the parties could even be, like a lawyer, so in case something happens to me, they can also interact. And this is something for, for the future for us to plan and to maybe discuss with the wider community which, which kind of schemes make, sense for various, scenarios."
    },
    {
      "speaker": "stephan",
      "time": "28:31",
      "start": 1711.02,
      "text": "Yeah. And so, as I understand it, the other thing I'm keen to ask is, how would it be implemented? Is this something that you would put inside the Trezor web wallet interface, or would it be a separate program?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "28:45",
      "start": 1725.02,
      "text": "actually, it's already implemented in the firmware, in our beta firmware, and, you just, instruct the Trezor via the web wallet that you want to perform the recovery of the shares or initialization, and the whole process is being done on, on the device. This has, one, big advantage and, obviously these shares, are much stronger if they are properly distributed among different- geographical areas, and, in, in, in the future, we would like to make this process totally independent of the computer, so you could just have a, have a power bank and a Trezor and travel all across these locations, so you can, you can recover them without, without a computer. So that's why the full process, is being done now on Trezor device."
    },
    {
      "speaker": "stephan",
      "time": "29:41",
      "start": 1781.45,
      "text": "Right. Is that, is that Trezor One or Trezor Model T only? It, it's just, Trezor Model T for now. Got it, got it. Okay, great. next thing I was, I was really keen to discuss is this concept of air gapping, and I think that is also now starting to become a little bit more front of cent-- front of mind for people. They're trying to be a little more security conscious. They are concerned about having to directly plug the device into the computer, and if the computer has malware There's a risk there. And so some of the ideas I have heard and seen, so obviously there is the cold card, I know they have the SD card, ability that you can transfer, you can ferry the transaction using that. And then the other idea that people are talking about now is QR codes. Do you have any thoughts there on whether that could be something coming in Trezor devices?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "30:31",
      "start": 1830.53,
      "text": "Yeah. first of all, I really do think that, even if you use USB connection, you are already air-gapped and protected from the malware There, obviously, there are some of the risks, that, might be hidden in the complexity of the USB stick. But that said, if you aren't using, USB stick, but then you are using SD card, there is another complexity hidden in the SD card driver or even in the file system driver. So you are just, there isn't no silver bullet, you are just, exchanging one set of trade-offs with, with the- Another. that said, we want to give, our users a choice. So, it's, obvious that, with Trezor Model T having an SD card slot, we will, or we are already working on, on that feature. So, in some of the future releases, Trezor Model T would be able to sign the PSBT transaction stored on the SD card. But, like I said, it's, it's not a, it's not a Silver bullet, because still, still, still, there is no like a physical connection, but still there is, there is data from the computer present on the, on the SD card, and, we would need to still audit the security of, not only just of the SD card drivers, but file system drivers and, even the PSBT parser, as well. And, another airgapping, method you mentioned is a QR code. This, is, even better it might seem, because, there are no, physical data present or, or how would I say? But, there was one moment in the past that really, struck me and, one of our external collaborators and, security researchers, Kristen Writer He found, buffer overflow in, BECH32 encoding or, or decoding, and it was properly disclosed to all other vendors. it was not, like a very critical bug because it w- could just introduce maybe two or three extra bytes, unexpected extra bytes. But then I realized, well, this can also be used to exploit, system via the QR code because, if you are able To, create a buffer overflow in, in address decoder basically, then you get, you can get that, piece of, piece of vulnerability over the QR code as well. So even that isn't, even that isn't like, one hundred percent secure, but still, this isn't kind of really esoteric or, not really possible, possible hacks, I would say. and also- Obvious, disadvantage is that you would need to have a camera on a hardware wallet, which, makes it, harder to, to produce and, well, it increases the price and increases the, the length of the process and so on. So, like I said earlier, the original Trezor Model, one was, Aim to be really simplistic, and we are hesitant about adding new features, and we are, it takes some time for us to, to evaluate that."
    },
    {
      "speaker": "stephan",
      "time": "34:12",
      "start": 2051.9,
      "text": "Right, I see. Yeah. And I mean, I suppose, yeah, I take your point that, QR codes aren't, are not a silver bullet, but I, I, I wonder whether they might be seen as at least one step closer, or at least one, you know, at least a bit closer to being harder to hack than, say, the SD card, option or the direct plug USB, right? Yeah, yeah, yeah."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "34:34",
      "start": 2074.45,
      "text": "yeah. There is one-- And, and yes, go on. I just wanted to say a And that is that user experience, hurts, because then you have to swap either SD cards or you can only fit, one kilobyte of data into QR code, and then the QR code is like really complex. So if you want to transmit, a regular Bitcoin transaction, which is usually Bigger than kilobyte, then you would need to exchange a set of QR codes and, well, it's, I think it might be more secure in some sense of, things, but then if you are making process, obscure, then, it is more error prone and then also security is hurt because, people can do mistakes and they will do, they will do mistakes."
    },
    {
      "speaker": "stephan",
      "time": "35:30",
      "start": 2130.3,
      "text": "Right, yeah, I mean, that's a fair point as well. You've got the process fatigue risk, but I suppose from-- I, I suppose for the people who are storing, you know, lots and lots of value, for them, they would think it's probably worthwhile. But I, I totally appreciate from your point of view as well, it's a business, and you've got to find that sweet spot in terms of what are people willing to pay for, right? but maybe you would have like different devices and like a really high-end device which has like all the bells"
    },
    {
      "speaker": "stephan",
      "time": "36:00",
      "start": 2159.62,
      "text": "Hardware, so hardware isn't an easy thing to make, so totally appreciate that as well. another point I think is interesting for listeners, and it's probably useful for them to know, and just from my recent interview with Andrew Chow, he was pointing out as well, he had some difficulties in trying to implement hardware wallet interface, H W I, with Trezor One versus Trezor Model T, and the reason was, with the Trezor One, you actually can't input the PIN physically on the device, you've actually got to do the scrambled PIN on the- computer, whereas with the Model T, you actually can enter the PIN directly on the device, and I think even if you want to try the passphrase recovery, you can do it directly on the Model T device. So listeners might be, might want to know that as well just for if they are thinking about, okay, future H2WI support and, you know, additional security advantages that come from being able to enter directly on the device."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "36:55",
      "start": 2214.56,
      "text": "Yeah, so, like we said earlier, Trezor Model T has a touch screen, so we, we really want to make it possible to enter every possible piece of information directly on the device, so it never touches, never touches the computer. And, like you said, it's not only limited to, to PIN. there is a really nice feature of Trezor Model T, and that's, if you, unless you enter the PIN, the USB communication is not even enabled. So,"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "37:29",
      "start": 2248.66,
      "text": "on Trezor Model One, you need to start the USB communication in order to perform this scrambled, PIN, entry. so that, that brings also another level of security. And with the passphrase, yeah, for Model One, you need to enter it on, on a computer. There's just, no other way yet, but we are exploring, various ways how to enter passphrase, directly on Trezor Model One, but because there are just two buttons, you are very limited, and we don't want to make this process awkward, because if this process is awkward, then- And usually you end up with a really simple passphrase kind of defeating the pur-purposes altogether. The Model T is much, better because you have a touchscreen, and, I personally use, rather complex passphrase, and still I am able to, to enter it directly, directly on the device. Great. Look, so let's talk"
    },
    {
      "speaker": "stephan",
      "time": "38:30",
      "start": 2310.08,
      "text": "a little bit about, you know, Trezor hacks and, some of these other angles. I suppose just firstly for the listeners, if you're a newbie listener, some of this stuff might-- it might scare you, but remember, it's all relative here, and you're better off using a hardware device than leaving it on an exchange. but that said, I think it's useful as well just to make everyone aware, you know, these are the hacks and so on that can occur. so- Some of the different ones I've seen, I mean, there's a range of them, right? So I think there was one around trying to infer from the, the signal, you know, what was the, the PIN or the passphrase. There's the other ones where if the attacker has physical access, to the device, that they're able to kind of reverse out or pull out the, the, the seed and the PIN and just access from there. did you wanna just discuss around what was your process around that and then try- Trying to mitigate against those."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "39:30",
      "start": 2370.02,
      "text": "Yeah, sure. So security, including physical security, is a very complex topic, and, I, I have to admit I'm also learning it, as it goes. And, what I learned, in the process is, everything, be it hardware or software, is hackable, and the only thing that changes is the price of the attack. So if the attacker is, motivated and has enough- resources, be that either people or, or money, they can get to your coins, even if they are moral standards are low, they can maybe mug you and torture you for, for, for, for, for the PIN or for the passphrase, so no, extraction from the device itself is needed, so to say. we've foreseen this, and like I said, BIP 39 was introduced in 2013 And, even that the original release of that standard, contained, a passphrase. So, it's an idea where you just don't use the seed store, into the, in the, in the device to generate the keys, but you also use that, passphrase, which is, being added in the mix and, only after providing the passphrase, you can generate, generate or derive the, the keys. One, great property Of this is that every passphrase is correct, so to say, because, there is no mechanism, to, to check the, the correctness of, of the passphrase. So what you can do is, you can, have small amounts of bitcoins stored with empty passphrases, then maybe, you can create a simple passphrase like airplane and put, some more bitcoins onto there, and then you can have like super- A super secret, super complex passphrase where you would put most of your holdings into, and in case you are in the trouble situation, you can show, the attacker this simple passphrase, and there's no other way or there's no way how to, to prove there is another secret passphrase. So that was the, that was the original idea, behind the passphrases, but also, the protection of the- physical security was another one in case the seed will, get compromised. Yeah,"
    },
    {
      "speaker": "stephan",
      "time": "42:05",
      "start": 2524.96,
      "text": "it's an interesting one because I think I, I'm I guess I'm just a little unsure how safe the passphrase part really can make you against, like, if they're, if they're there with you, right there. because i-in reality, they could just keep hitting you, right? They could just keep, you know, they could just keep hitting you until you give 'em everything, and they-- And who knows? I mean, they, they-- Because even if, if, if they're a smart attacker and they know how a Trezor works, or they know how pretty much every hardware wallet works with the passphrase, they At the same time, it's, it's there to provide some level of, protection. I think the other question that came up from some of the hardware hacks and so on, was around what length does your passphrase have to be to, to keep you safe? Because theoretically, if, an attacker gains physical access to your Trezor device, they-- and it's, you've run a very short passphrase, they may be able to brute force that, and it might not take them that long to do that That kind of attack. So can you just tell us a little bit around, of your thoughts around what length does it need to be to be safe?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "43:15",
      "start": 2594.89,
      "text": "Yeah. So, we published, a post on our blog titled, \"Easier passphrase strong enough,\" where there are lots of, good practices and, recommendations how to come up with a good, passphrase. you could either use, use a die swayer to generate, basically another sentence of words that you memorize, or you can, use a random generator to create, create, lowercase sequence of, of characters, and so on. And, there is a even a nice table included in the blog post and, for example, Right now, if you use, thirteen lowercase letters, for the passphrase, the attack would cost around a billion dollars. So obviously, that's a lot. this will change, in the following ten years because we have better computers every year, but still, even in, two thousand and thirty, the cost of this attack would be ten million dollars. And then we could- To discuss like if an attacker has, one billion dollar right now, what is easy, easier to perform, like perform, a hardware level attack on some very sophisticated, hardware wallet or to perform a brute force, attack on, on a passphrase. So we are, We are basically providing all these means to make it harder for an attacker, but in the end, it's the resources of the attacker that matters, and the other important factor is time. We want to make it as hard as possible for the attacker to attack that effectively, and if the attack takes, I don't know, two weeks to perform, then we are pretty much on the safe side because, in, if I do realize during that time Two weeks that my, hardware wallet is missing, I can still send the coins out of this, device, and that's a really big, big improvement because for example, if your, I don't know, credit card, is, is, is, is hacked, you just need to replace, replace the device, but in that case, you can just generate a new passphrase and send, send send the coins to another passphrase, for example."
    },
    {
      "speaker": "stephan",
      "time": "45:55",
      "start": 2754.82,
      "text": "Right, yeah, and I think the other thing as well is the length of the passphrase that's required to make it safe. So some of the best practices and so on, like if you look at, say, I think there was a cold, cold bit blog post, and I think from there, it was basically saying, okay, remember, humans are very bad at doing random or generating random numbers or characters, best to use these dice, Dice where lists, and so you, you might, you know, sit there rolling dice and come up with a list of six or seven words and use that as your passphrase to help, you know, keep you more safe against the attacker. But that also does bring in another whole layer because now you have to think about that from backups and restoration point of view, because let's say, I need to think estate planning, you know, how do I pass it on to my heirs or to my family? That's also an additional consideration, and the challenge then, I suppose, is there is a risk that the user will not correctly backup the passphrase as well as the seed and pass it and put it in some way that their family can access it when they die."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "47:05",
      "start": 2824.98,
      "text": "Yeah, yeah, that's correct."
    },
    {
      "speaker": "stephan",
      "time": "47:09",
      "start": 2829.28,
      "text": "Yeah, so I suppose that's just the main risk I might just call out for the listeners, but absolutely the passphrase is a good recommended practice, but just, just be aware of that, backup and restoration and estate planning aspect of it as well. Okay, so let's talk about now privacy. So this is also another topic that people are becoming a little bit more aware on and are starting to take some further steps. I suppose the one, the- Right now, if a newbie just buys a Trezor and they just use it, and they plug in, and they go to, you know, wallet.trezor.io and so on, and they initialize that device They are at that point, are they sharing their xPub, the way to generate all their addresses, with the Trezor web server?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "47:58",
      "start": 2877.56,
      "text": "at the moment, that's correct. you are sharing the, the xPub with the, whatever backend you are using. so if you are using, our backends, that's true. also, it's a little bit more complicated. It depends on, on the coin. for some coin, you are Not, sharing the whole xPub, just the individual addresses, and it, it depends on what, whether there is a, there is an optimization for key derivation on, on the server or not. But that said, there, is a way how you can use, our, our backend, run locally. So if you don't, want to do that, you can, download the our, our backend sources because these are also open-source Source and run them, for yourself."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "48:54",
      "start": 2934.0,
      "text": "Another option, how to, initialize the device, without, xPub being shared, for example, is, you can install, Python Trezor package, which contains, TrezorCTL command line, tool, and, this can, perform most of the stuff you want to do with your device, so either initializing or getting addresses or sending transactions, but that's, a little bit, too low level for regular use, but for initialization of the device, it's, just, perfect. And there, there is always Electrum, like we said, you can use Electrum And then, you can connect to whatever, address server you want to use, even or your own one. And when it comes to privacy, we have a re-really big, bulk of improvements coming up, end of this year or maybe beginning of the next year, and, the idea is that we want to, create, desktop- Software called, Trezor Suite. So, it will do everything that the current web wallet does, but in a desktop environment. And then there would be an option for the user to la-run the local Bitcoin Core instance so the Trezor Suite, software could connect to it directly, or you could use Tor to, to connect to our backends if you don't want to run, if you don't- You don't want to run a local Bitcoin Core instance, but, you want to use our servers, but still you, want to protect your privacy. And with, this Trezor suit, we want to make this process as easy as possible. So our current idea is to just have like a really, really simple, checkbox, like I want to run the Bitcoin Core instance, locally, and if you check it, it will, do everything for you. You and connect to, to the fully synced, synced instance or even, if you want to use our beacon swiato again, we want to make it, as easy as, possible for, for the user."
    },
    {
      "speaker": "stephan",
      "time": "51:26",
      "start": 3085.69,
      "text": "That's really good. I, I didn't know about, Trezor Suite coming. is that a relatively new thing?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "51:32",
      "start": 3091.75,
      "text": "Well, we've been, cooking that for quite some time, but there are a lot of, a lot of challenges and, and, not only technical, ones, but also a lot of, discussions about how the user experience should look and, yeah, like I said, we want to make, it as easy as possible, because, That's, that's, that's our, that's our goal, we want to make things, secure but also very, very usable, because only if they are easy to use, they are, indeed secure."
    },
    {
      "speaker": "stephan",
      "time": "52:07",
      "start": 3127.46,
      "text": "Got it. Okay, yeah, so look, let me just summarize that for the listeners, if they're a newbie and they couldn't quite follow everything there. Basically, right now, if you use a Trezor with the standard web wallet, if you just go to wallet.trezor.io, you are giving up your xPub when you first initialize, meaning that the Trezor web server can, you know, Kind of know your balances, right? Because that's, that's how it knows your balances. And if you use it on Electrum without using something like Electrum Personal Server, Electrum X, or Electrum Rust Server, you're kind of giving off the bal- you're giving off the transaction data to the public server. But the good part is, if Trezor Suite is coming, then that is a potential way that you can set up wholly on your own computer and/or using Tor in such a way that you're not giving up as much of your privacy. Or if you're using fully own your own local Bitcoin core, then it's done in a way where you're not giving up any of your own, information about your balances to the Trezor web server. Would you say that's a fair summary?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "53:10",
      "start": 3189.87,
      "text": "Yeah, yeah, I think that's correct. Also, there is another option, like you mentioned, at the beginning of the interview, there is a project called, HWI, which allows you to connect, hardware wallet to, local running Bitcoin, Bitcoin- Bitcoin Core instance, so there's, that's an, that's also an option, but it might be, tricky for, for common people to, to use. But that, that's, that's the best thing you can do because, only if you are, running your own, Bitcoin Core instance, then you can be really sure there is no middleman be-f-between you and the Bitcoin blockchain."
    },
    {
      "speaker": "stephan",
      "time": "53:53",
      "start": 3232.83,
      "text": "Fantastic. Alright, let's talk about, the question of Bitcoin only. So, I think some, if I were to try and just reflect some of the, what I'm gonna call, quote unquote, Bitcoin community sentiment, I think some of the more hardcore Bitcoiners feel like they get a bit paranoid when there's an update coming on their Trezor device, because they're worried that, oh, I don't wanna support, I don't care about shitcoin. Support. I just wanna keep my Bitcoin safe. is there a additional risk there around having, other altcoins in, or support for them, versus the kind of Bitcoin only? But at the same time, I wanna be fair to you, I wanna recognize you're a business, and so you've gotta, you know, you've gotta, make sales, so I don't, fault you for that. But what are your thoughts around the idea of having the-- And I don't, I don't know if this is a topic you might have touched Bitcoin only firmware."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "54:54",
      "start": 3293.69,
      "text": "Yeah. So obviously, we, we were born and raised in, Bitcoin community and this is what we are coming from. And, I'm one hundred percent Bitcoin, I don't own any, any other coins, we are Bitcoin maximalists. But, to be, to be frank, if it weren't for, altcoins Coins, we wouldn't survive the years, two thousand and seventeen and eighteen, and this is something not a lot of people, realize. And, it's very easy for the new hardware wallets that will, that came up, recently to say, \"All right, so we, we don't do, do, do shit coins.\" And personally, if, the situation wasn't that bad, two years ago, I wouldn't, wouldn't, add, these alternative coins as well But there are also some, some voices, among the company and outside of the company that are basically saying, \"All right, so, there are people that will get, into altcoins and then they realize, there is only Bitcoin, so that's also kind of, a little bit more stressful maybe, but also, an onboarding of, new Bitcoin users through these altcoins, acquisitions.\" So, there is more things to that. And, when it comes to, frequency of the updates, people are saying, \"Oh, you are just adding some, altcoin stuff, and I need to update all the time.\" Well, that's not really the case because, every time there is a firmware update, there is some Bitcoin, or management, feature also being added. So I don't rem- Remember any firmware update that, included only Altcoin related changes. And, of course, people are asking for Bitcoin only firmware, and we've d-done some, steps to that already. And it would, obviously make our release process a little bit harder because then we will, will release, two sets of features in two firmwares, on each update, but This is something we are going to do, and, I'm not sure if it will be the next update or the update after, afterwards, but yeah, we would really like to deliver that functionality to, to our users. Or this stripped down, functionality in, Bitcoin only firmware to our users. Great."
    },
    {
      "speaker": "stephan",
      "time": "57:45",
      "start": 3465.07,
      "text": "Okay. Cool. yeah, I think, oh, so FIDO2 authentication. So, did you wanna just touch on that as a feature? what is it and what, what should the Bitcoiners be thinking about when they wanna use FIDO2? Yeah."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "58:00",
      "start": 3480.3,
      "text": "So I would say most of the people that are interested in Bitcoin got somehow in contact with- U2F because of, some of the exchanges, are introducing, various forms of second factor authentications. So second factor authentication is a very simple concept when you have, something, you, have and, something you know. And in the case of, U2F, the something you have is, a hardware token and something you know is the password. So when you are logging into the application, or web application, you need to provide a username and a password, and then the website will ask you for, confirmation on, on a, or on a hardware token, and usually that's, YubiKey because the, that's the company that pioneered, pioneered that approach. And that's, that's better than the second factor authentications via SMS, for example, because, the SMS network could be somehow intercepted and, decoded, and there were also a lot of, social, engineering attacks on, calling to mobile phone operators and persuading them to transfer the SIM cards to some other person. So there are- There are a lot of other, other issues. And, Phidio two is, another generation of such, authentication method, and it's backwards compatible with U2F, so,"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "59:47",
      "start": 3587.35,
      "text": "it could work the same way as the old, U2F authentication, but also includes, something that I call passwordless authentication, and there are again, two Two factors included, something you know, that's a hardware token, and, sorry, something you have, that's a hardware token, and something you know, and that's, that's a PIN to a hardware token. So if you have, a hardware token that is protected by a PIN, you can get rid of the password basically, and if you have got rid of the password, you can very easily get rid of the username because you can use some public key, to identify you In the system instead of the username. So what FireTwo loves you is to, or it provides you a very simple and standardized way for a system, application, web application to ask you for, identity, and then you can provide it using a hardware device, and the hardware device can, verify the, the correct, person is using that because there is pin involved in the process. And this process is really straightforward because it gets, rid of all these, hassles. and, I've been reading about five or two for since maybe two years, we were reading some preliminary drafts, of the specification, and that seemed like a really great thing to do, but only recently, a week ago, my colleague presented the feed- Two in our firmware, and I was like totally blown away, like the user experience of Fido Two on Model T was just, just amazing. It would, it would just, show the name of the service on the display and your, identity be, being some, username in the system, for example, and then you would just scroll among the identities on the device, if there are more, you can of course register, Twice on the same service, and then you just confirm it on, on a Trezor, and you are automatically logged in, no password, nothing else."
    },
    {
      "speaker": "stephan",
      "time": "01:02:11",
      "start": 3731.79,
      "text": "Yeah, that's great. I, and, I definitely can reflect from my own use with the, Model T. It, it is quite a-- I haven't had a chance to use Five O Two on it, obviously, but I, I, I do notice the, user interface is quite, easy on, easy to use. so look, Pavol, Questions I had for you, but did you have any closing thoughts on what we can expect to see coming from Satoshi Labs and Trezor devices? I, I mean, you mentioned the Trezor Suite before, but, just let us know if there's anything you would like to say about Trezor right now?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "01:02:45",
      "start": 3765.76,
      "text": "Yeah, so I think we covered most of the most exciting changes that are in the pipeline, like Shamir backup or Fido2 or PSBT via SD card. And these things are in the pipeline for some time already, but it takes some time to, to fully understand the, the feature when it, when it's not, the feature designed by us, for example, like Fido2. Also, it's very, very hard to even- Come up with your own, feature, for example, like Shamir, so there are a lot of discussions, and this, this takes some time and also lots of, testing and implementing. But the good news is all of these, are already in, in a like a testing phase, internal testing phase. So I'm really hope that this will be rolled out, very, very, very soon. And then the big, leap would be the Trezor Suite, the desktop application for Trezor, that I mentioned, with all these, extra features that were just not possible when, using the web application, so either it's Tor connection to backend servers or connecting to a local Bitcoin Core instance, and I'm really excited to, to see that because, I think we, will, make, it even, even, even better for people to be private and sovereign. And, while maintaining the, the same level of user experience they are really used to."
    },
    {
      "speaker": "stephan",
      "time": "01:04:24",
      "start": 3864.07,
      "text": "That's fantastic. Yeah, I'm definitely, looking forward to seeing the Trezor Suite coming out and some of those features, as you mentioned, I think I'm, I'll definitely be keen to give those a try. so look, I think that's basically it, but yeah, obviously, before we let you go, Pavol, can you just tell my listeners where they can find you online and if they wanna get a Trezor, where should they go?"
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "01:04:43",
      "start": 3883.5,
      "text": "Yeah, sure the easiest way how to contact me is on Twitter. I'm, Pavel Rusnak on Twitter. Trezor also has its Twitter account. It's, twitter.com/trezor. Everything we do is open source, like I said. So, github.com/trezor. There are all, all possible sources to firmware, backends, and obviously you can, find me, on GitHub among the GitHub issues, as well. We do all the development in public, so you can see all the features we are working on. And, the Trezor website is, trezor.io, where you can get your devices. And we have a, a small gift for our listeners because, this, episode is episode one hundred, if I'm correct. Yes, it is. So we, decided to give, our, our listeners a promo code, so if you use promo- Code SLP one hundred in our Trezor shop, you will get a discount for, for Trezors, and this promo code is valid for one week. Fantastic."
    },
    {
      "speaker": "stephan",
      "time": "01:05:54",
      "start": 3954.66,
      "text": "Alright, well, I think that's pretty much going to do it for us. So thank you again for joining me today."
    },
    {
      "speaker": "pavol_rusnak_stick",
      "time": "01:05:59",
      "start": 3959.67,
      "text": "Thank you very much for inviting me, and it was nice to, to see you and to chat in virtual person."
    },
    {
      "speaker": "stephan",
      "time": "01:06:07",
      "start": 3967.27,
      "text": "Hope you guys enjoyed that interview. Remember, you can get the show notes and subscribe to the show on my website, stephanlivera dot com. Also, just a reminder to share this episode and the hardware wallet interview series with your friends so they don't leave their bitcoins on an exchange and risk getting wrecked. That's it from me guys, thank you, and I will see you in the citadels."
    }
  ]
}
