{
  "episodeId": "SLP104",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "douglas_bakkum": {
      "name": "Douglas Bakkum",
      "role": "guest",
      "tag": "DOUGLAS"
    },
    "jonas_schnelli": {
      "name": "Jonas Schnelli",
      "role": "guest",
      "tag": "JONAS"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:08",
      "start": 8.37,
      "text": "Hi and welcome to the Stephan Livera podcast focused on Bitcoin and Austrian economics. Today, for episode one hundred and four, we are speaking with Jonas Schnelli and Douglas Bakkum of Shift Crypto Security. But first, let me introduce the sponsors of the podcast. So firstly, check out Kraken. They are one of the world's leading Bitcoin exchanges. They've consistently impressed me in the past The way they operate, they've got a really strong focus on security with Kraken Security Labs. They're one of the longest standing Bitcoin exchanges. They've got a high quality platform offering some of the best liquidity you can find in this industry. There's high trading volume and low fees with no minimum or hidden fees. Kraken have twenty four seven support and on the institutional and business solution side, they are providing best in class accounting, reconciliation and reporting services for cryptocurrency hedge funds, asset managers and fund administrators. Kraken have an OTC desk for those higher touch, large block trades. They offer five fiat currencies and also offer margin and futures trading. To learn more and sign up, go to the Kraken link in the show notes. Next up is Unchained Capital. They're a Bitcoin financial services company offering a two of three keys multi-signature vault product. You can use Trezor or Ledger wallets, and it's really easy to set up. The web interface is very intuitive, and in doing so, you can distribute your- Your keys, giving you some additional level of protection there. And on the other side, Unchained also offer Bitcoin collateralized loans, so you can get USD liquidity without selling your bitcoins, meaning you don't trigger a capital gains event. So your bitcoin is stored in a dedicated multisig address under what's called collaborative custody. And so if you wanna learn a little bit more about that, make sure you go to the Unchained Capital link in the show notes. Okay, so for episode one hundred and four, we We are carrying on with the hardware wallet interview series, so my guests today are Jonas Schnelli and Douglas Bakkum. Jonas is a Bitcoin core developer and maintainer, he's very well known within the Bitcoin world. He is also a co-founder of Shift Crypto, and Douglas Bakkum is the CEO of Shift Crypto, and this is the company behind the digital BitBox and the upcoming BitBox 02 hardware wallet. So, onto the interview. Jonas and Douglas, welcome to the show. Thank you very much for having us."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "02:33",
      "start": 153.42,
      "text": "Yeah, thanks. Excited to be here."
    },
    {
      "speaker": "stephan",
      "time": "02:35",
      "start": 155.24,
      "text": "So, look, obviously we're doing this hardware wallet series, I wanted to discuss with you guys as well from Shift Crypto Security. So, look, let's just start with a bit of background on yourselves, on you guys and what your role is with Shift Crypto Security. So, Jonas, let's start with you."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "02:53",
      "start": 172.63,
      "text": "Yeah, Douglas, we met, I think, back in two thousand and fourteen, when- That when Douglas showed me at, one of those Bitcoin meetups in Zurich, his, his, piece of hardware, I was quite impressed because it was, yeah, back then, two thousand and fourteen, not much hardware wallets were around, I think only Trezor was really, Or was, was quality wise an acceptable, thing? And, yeah, I'm not even sure if they"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "03:23",
      "start": 203.2,
      "text": "released then."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "03:24",
      "start": 204.2,
      "text": "Yeah, it could be. I mean, you started certainly before, they have released with your, your PCB design and stuff. And, yeah, I was really impressed, and I, I knew that, I mean, I, I still be aware that key storage is one of the crucial, points in the whole Bitcoin space. it's so hard to really store or protect your private keys. And, I think, I, I, I saw that this is gonna be a huge thing, and somehow we need multiple, multiple vendors on that level, otherwise it's, it's going to be, kind of a systemic risk for the whole, Bitcoin system. And as, as you may a-are aware, I'm in for the long term, for the decades rather than the years, and I was working on Bitcoin Core and still do, most of my time, and I knew this This needs, kind of support. Then I started to collaborate with Douglas, and at some point, we founded a company together, and here we are."
    },
    {
      "speaker": "stephan",
      "time": "04:25",
      "start": 265.18,
      "text": "Let's hear a little bit from you, Douglas."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "04:27",
      "start": 267.02,
      "text": "Yeah, I'll have a, I guess, a bit of, bit of a different take. well, first of all, your question, like, what, what are our roles? So Jonas, right now, he's the president of the company. We co-founded the company back in October of 2015. So that's probably a year after we had actually,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "04:47",
      "start": 286.88,
      "text": "On the project, I was in a completely different, different life than I am now. So I was actually a neuroscientist at the university here, I was a group leader, at ATEHA University. interestingly enough, our company is a spin-off of a neuroscience lab at ETH. But, yeah, it's, it's, it's, quite a stretch to figure out how that connection works, but basically, it was more on the neuroengineering side. So that lab, that laboratory would make, electronic devices, including PCB devices, ASICs, and so on, in order to help study neurons better and help advance neuroscience. And so through that, but also before that, I had some, mechanical engineering. background, and robotics and AI and stuff like that. so through that we get the, I guess some of the technical foundations, for building PCBs, dealing with data processors, how to, how to write firmware, how to deal with USB communication and things like that. so we, that really gave a technical foundation. and let's see. So yeah, for myself, I started working on it in my spare time then. So I guess I was the inventor of the original BitBox, and, what was the, the story back then, I guess? I started learning about Bitcoin around 2013, Took me about two weeks after I bought my first Bitcoin until I was actually comfortable holding it. And so, given a technical background, I kinda understood some of the security implications and things like that. And it really took me a long time just to research and actually implement, a solution where I actually felt comfortable. And so I was like, \"Okay, this is, this is never gonna be adopted if it, if it takes me this long or takes anyone this long, to get used to it.\" And so, at the time, there were no hardware wallets on the market,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "06:42",
      "start": 402.48,
      "text": "Talking about it, Ledger before they became Ledger was talking about it, but also at the same time, if you're around, you might remember, a lot of scams in hardware, especially with the Bitcoin miners, and a lot of people losing money through presales and things like that. And so it was a big question to me if, actually something would come out of it. And so I just decided, okay, what can I do? I'll just try to make something myself. And so just in my spare time, I started making it,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "07:12",
      "start": 432.5,
      "text": "in Switzerland, and so we met each other at the meetup, we encouraged each other, and it became a really nice fit. So I was working on basically everything that you can touch, so like the hardware, but also the firmware on it. And Jonas has a long background in, entrepreneurship, especially with mobile apps, and so he had a, a great skill set for actually building the front end, what users would see, in interacting with the device. And so Yeah, we tried to do it ourselves, make, make a whole system, and got a lot of feed-- great feedback, great encouragement from the, crypto community in Switzerland, which is, despite being a small country, it's quite strong. and yeah, and we ended up founding the company together."
    },
    {
      "speaker": "stephan",
      "time": "07:56",
      "start": 475.75,
      "text": "Excellent. Let's, let's talk a little bit about the BitBox 01 then. So there were-- There's definitely some people amongst the Bitcoin community who are like Bit- BitBox fans, right? Like I see, I even, On some of the podcasts, people mentioned the BitBox as well, so tell us a little bit about what was your experience creating the BitBox 01?"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "08:14",
      "start": 494.09,
      "text": "Yeah, so I, I mean, I had some basic, you know, background in PCB design and things like that. I've been an academic my whole life through, so this is actually my first experience in, like- I don't know if you can call it the real world or not. In a, in, in a, in a different world, although there's a lot of parallels, which I find interesting. And so is, and be, being an academic, being a scientist by background, I like to, you know, kind of figure things out on my own. so do a lot, a lot of research a-and learn, become an expert through that, through, trying things. So one of the very first things I did with the BitBox 02, for example, was,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "08:56",
      "start": 536.01,
      "text": "And I wrote my own like big number, library to fit into that. And just to learn how, you know, what, what really it is I'm getting into, and what are all the factors involved, like the side channel risks, you know, the need for, you know, good entropy for nonce, nonce protection and things like that. And so really, really dig in deep, and that was a great, great experience, And, yeah, and then kinda going from there. And of course, if you wanna make something, turn something from, you know, just, it, it's really basi- in, in the simplest words, you could call it a hobby, right? If I'm doing in my spare time. to take something from a hobby and actually make it into a, a professional production-grade device where now all of a sudden you don't have to worry about yourself being responsible for yourself, but you also have to be responsible for a broader community. you know, that's that's, that's a big, that's a big thing, and so I took it seriously. before we launched the BitBox 01, of course, I made sure to, deal with or start communicating with the, the community, especially the, the security experts, audit firmware, talk to different companies, talk to different experts in cryptocurrency and in Bitcoin specifically, and try to really, you know, take responsibility for it. I'll, I'll stop, I'll stop there. You can continue."
    },
    {
      "speaker": "stephan",
      "time": "10:18",
      "start": 618.46,
      "text": "Great. Yeah, Jonas, did you wanna add any comments around your experiences with Bit- BitBox 01?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "10:25",
      "start": 624.9,
      "text": "my side, yeah. I mean, as Douglas said, it was starting-- it's coming out from a hobby, and at some point, if you decide to do it, to do a product, there's a whole new, level, going up because it's like you need to deal with, limited resources, you need to deal with packaging, with the whole- Quality insurance and, and, and, and this is huge and coming from, from open source where you have somehow it feels like unlimited time to polish stuff it certainly, was in a, in a mode where we had to ship at some point, so y-you need to have, you need to have a great resource management, and when it then comes to product quality, which includes, security and stuff that's pretty new, it gets complicated. And I think what we learned is how we can turn a hobby, into something that, that can be, can, can be produced in large masses with, with a good Quality and, BitBox 01 was mainly, in my opinion, about, scaling up, getting ready."
    },
    {
      "speaker": "stephan",
      "time": "11:33",
      "start": 692.64,
      "text": "Great. I think the listeners will be interested to hear a little bit about your experiences with dealing with, obviously, hardware wallet hacks, right? So there have been many, but basically every wallet has had some ha-kind of hack or some sort of attack on it. And I know Saleem Rashid wrote a post in November 2018, and it's called \"Breaking Into BitBox.\" And so there's a few different po-parts there that might be- Interesting, just to talk through from your point of view, and we can sort of talk about, you know, what, what, what went wrong with those, but and then potentially what's like the improvement with BitBox 02. So there were a couple, I, I just from reading through that post, he spoke about one aspect around, BIP 32, the basically coming to how the, the, it was around the hidden wallet and understanding like the way the chain code, and apparently it was flipped, and so that enabled an attacker to potentially get, you Another, component around, a potential man-in-the-middle attack that Saleem mentioned. Did you wanna just, discuss with your thoughts on those attacks? And,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "12:35",
      "start": 755.24,
      "text": "yeah, sure. I, I can give it a, give it a shot first. so, yeah, first of all, for, for those who don't know, Saleem, is a really, really smart guy. He's made a name for himself, as a white hat hacker of hardware wallets in particular, and he's responsibly disclosed vulnerabilities to us in the past, but also and so I, I personally consider him probably one of the best, if not the best expert in hardware, hardware wallet security in the industry. And so in, in one sense, it's kind of a bit of a, I guess, an initiation process for hardware wallet vendors as they mature. So in that sense, it can be a, a bit of a badge of an honor, badge of honor. but on the other hand, of course, it's always, quite humbling to, be publicly faced with, you know, bugs and, and mistakes made"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "13:25",
      "start": 805.49,
      "text": "Not to shy away from, because in the end, it's all about making security better for the end users, and of course, all sides are aligned with that. And so, yeah, mi-mistakes happen. one of the difficulties with, security in general, especially for, for Bitcoin and cryptocurrencies, is that, yes, like I said before, we had, we did get audits, but, you know, getting the, the domain specific, knowledge i-is is difficult. And so like the high level concepts, oftentimes the security companies, the security experts just, i-it's not in their frame of mind, it's not in, not in their, the tool, the toolset they use to look at security vulnerabilities and things like that. And so it really takes, You know, special people, with, with the deep, deep level interest, not only, not only deep level interest, but also a, a good grasp of the high level concepts, to, to get security right, and Salim definitely has that. And so, we wanna be, very transparent about it, Very open about it, really encourage and reward community feedback, to help our security, that's why we have a bug bounty program and so on. these particular, vulnerabilities you list, yeah, they're, they're mistakes, that happen, definitely, parts that got o-overlooked through our security process, both internally and, and externally. So we're very thankful for Celine pointing it out. Very lucky that, these particular vulnerabilities- Abilities weren't, weren't permanent, so they could be fixed, and they were fixed in time, through the responsible disclosure process that individuals didn't get, affected. and so we're, we're conscious of the fact that probably there's gonna be more mistakes, not only by us, by everyone else in the future, and so we wanna, you know, try, try to, get the best security experts, Slim and so on, to a-also be able to help with us. I wanna say one of the, Blog post, so of course, making mistakes with security, is humbling, they do happen, you have to fix it, of course. But the thing that probably hurt, hurt me personally the most was, some language later about, I guess losing motivation, to work with us. and so I, I just wanted to, address this topic, given the opportunity. And so I, I think a lot of that came up, out of miscommunication as, as a lot of, Issues do. so we still do have a good relationship with him. we're trying to continuously improve our bug bounty program, that it is attractive to people. And Salim, he has, taken a few of our next generation BitBoxes, and so he has a couple of those at home, ready to hack on. And so we're looking forward to continuing, this relationship with him and others."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "16:24",
      "start": 983.87,
      "text": "Yeah, he certainly has some hard knots to crack now."
    },
    {
      "speaker": "stephan",
      "time": "16:28",
      "start": 987.61,
      "text": "Yeah, so as I understand, one of the points and potentially this is an improvement from the BitBox 01 to BitBox 02 is having a screen on the device. So I think, that is, so for listeners, if you remember from the earlier episode with Michael Flaxman, he spoke about this concept of making sure that when you do a transaction, you verify it on the, in the most secure location. And so I understand with the BitBox 02, there is a screen on the device. And now that is a security feature that the user should be making full use of, such that they're not trusting what is on their computer screen, they're trusting what's on the physical device."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "17:06",
      "start": 1026.3,
      "text": "Yeah. I mean, speaking for the BitBox one, the concept there was that you pair it with a smartphone, in order that you have a second factor that would then verify in a secure channel, what your hardware wallet is going to sign. And of course, it was a different- Security model, it's probably debatable whether, with, with an on-screen, i-it's more secure. On the other hand, it gives way more opportunity to interact with the s-stuff you see on the screen, so you can open, you can see, you can verify things way more easily, which then comes down to what is security, in general, is it to show stuff or is it to make it accessible that user actually can verify things? And if, if your address is on a like- on, on screen where nobody really can read the characters, then it's, again, maybe higher security if you can verify that on, on a second factor smartphone. I guess it's all about options, and now with the BitBox 2 we have a screen on, on, on the device so people can actually verify, directly on the device."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "18:14",
      "start": 1093.72,
      "text": "Oh, I was, I was just gonna add a little bit to that also. So, yeah, the, the concept with the BitBox 01, originally called Digital BitBox, was, yeah, to use a, a, a secure connection to a, a mobile app, and then that basically serves as a secure remote screen, for your device. Now, that said, I think i-it is possible to have a, a similar level of security using that setup, but the drawback then is, you have another interface, that you have to The interface where communication has to go, and so it's opening up the attack vector surface a bit, but if you get it right, I think the security can be, can be similar, it's just a lot easier if you have a, a screen on your device, and so, to, to, to avoid a lot of these, these other things you have to think about."
    },
    {
      "speaker": "stephan",
      "time": "19:02",
      "start": 1142.48,
      "text": "So I think the, if I were to summarize then, one, and I think part of that is a fair point, is that sometimes you've got to make sure, obviously there's If you're giving it, you're making it easier for the user to use a hardware wallet as opposed to making it difficult for them, then there might be more incentive that they use a hardware wallet rather than say, leave it on the exchange, which is everyone agrees that's the worst practice, right? But, yeah, but as you mentioned, there is, there is an additional attack vector, and in Salim's post, he mentions it was literally the man-in-the-middle attack potential at the point of the ECDH, the Diffie-Hellman key exchange, that Attacker to try to insert themselves into that and obviously, ex-exploit from that point of view. But yeah, okay. So look, let's, let's talk about the new device then. So the BitBox 02. Douglas, did you wanna just give us a bit of an overview? Sure."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "19:58",
      "start": 1198.25,
      "text": "So the BitBox 02, let's see, the current status is it's, we're doing pre-sales right now. I know I mentioned earlier all these problems with pre-sales in two thousand and thirteen, but we are doing pre-sales right now. The, the difference though is we actually have, the product, existing. we started a beta program, a few months ago, so we actually sent devices out to beta users, to mainly get feedback on the UX testing. In the meantime, we've been going through, security audits, and we didn't wanna start presales until the security audits were actually finalized, and they are now. And so, production began and we'll start to ship in September, ideally. so that's the current status. What's new? we already mentioned the screen, the screen is new. so some other things that are new, include, Let's see. a USB-C, excuse me, a USB-C, port so you can plug it into, devices directly. in particular in the EU, there's been, a lot of legislation, talk about, reducing cable waste. And so mo-mobile phones in particular, are supposed to have a, a single, form factor for, for charging, which is gonna be USB-C. And so the general trend in mobile devices, also, laptops, is going- Towards USB-C, so we want to be future ready with that. our, our desktop app itself currently runs on, on laptop, but it's also, we also designed it from the ground up to work with mobile, and so that'll come out soon, and so then you can use our devices with mobile. I think that'll be a, a, a nice feature. one of the things we're very excited about is, this touch slider, mechanism, and what that means is, so, so the device is, a small, but Size, device. We have a screen on top, that covers most of the top space, and then on the sides of the device, we have two areas for touch sliders. And so we think you can do a lot of really interesting UX, with this, so- Having to do with, like password entry or mnemonic seed entry or just scrolling through your addresses when you need to verify, where you're sending coins and things like that. And so we're quite excited about that. We think it, has a few advantages in the sense that you can do things faster, you can do things easier, we think it can be a more intuitive UX. Of course, there's probably still some rough edges around it now, but we think it has the potential for all these things. Also, we redesigned the, the security concept from the ground up. So similar to the BitBox 01, we, we took, what we think is kind of the best of, of both worlds from Ledger and Trezor in, in the sense of a unique, dual chip approach. we started that in BitBox 01. I know Coldcard is now doing that with theirs, and we tried to further that with, with the BitBox 02. and I, I don't know if, I, I can stop there, we can get into the security of that a little bit later, but just from a high level, that's, what's new. I'd also like to say, with the BitBox 01, we also, learned a lot through that process in feedback from them. And so when designing the BitBox 02, we tried to take what works, with the BitBox 01 and keep that, and add in the, the extra features that people are asking for, the screen and so on. some of the things that worked with the BitBox 01 are the, the form factor, the size, it's portable, you can keep it in your pocket. people liked a lot the discrete design. so if you pull it out, you're not automatically advertising that you have,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "23:58",
      "start": 1438.08,
      "text": "Some of the other, vendors that would be the case. and of course, one of the biggest distinguishing factors is, the SD card slot, which we started in the BitBox 01, and, Just to touch on that a little bit, part of the feedback we get from users, really is, you know, usability still remains maybe one of the highest, issues with, adoption and also, just using hardware wallets or any, any type of thing you interface with, cryptocurrencies. and so a lot of feedback we get from new users in particular and our resellers is, this concept of mnemonic anxiety. And so I guess your, your- Your, your listeners are well aware of, mnemonic phrases and things like that, but new users aren't, and it's a foreign concept to them. They don't really understand why they're writing words down onto a piece of paper. And people say it takes them, you know, twenty minutes, thirty minutes to write down very, very carefully each word and then go through the whole process to verify that what they wrote down is correct. It's just really confusing, really stressful. And so with the, micro SD card slot we basically reduced that to, something that's really, really understandable, so backup is understandable by people and it's instant. so once you create the wallet, we automatically save the backup onto the, SD card. So it's very fast, very easy setup, also very fast, very easy recovery. we, we think, we've gotten a lot of feedback that people really like that. of course, with the new device, now that we have a screen, we, we also wanna, you Make it easy for, the more experienced users to, be comfortable with our device, so we do have an option for writing down mnemonic seeds on paper."
    },
    {
      "speaker": "stephan",
      "time": "25:51",
      "start": 1551.39,
      "text": "Great. You mentioned earlier the dual chip approach, would you mind, explaining a little bit further on that?"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "25:57",
      "start": 1557.44,
      "text": "Yeah, sure. So there's, in, in your, in your past podcast, there's also been some debate about, you know, open source versus closed source, secure elements versus general purpose microcontrollers. And so by the dual chip approach, what we're doing is we take a general purpose microcontroller, we put open source code onto it, so we can get all the benefits of, security that come with open source, in terms of, you know, people, people being able to, verify, what you say Is true is actually true. I think open source, something that doesn't get talked about, about a lot, but else is also very important is the internal pressure on yourself. So if you're really, you know opening your coat and showing, showing the world everything, you know, it gives you more incentive to actually do the right thing and pay more attention to the security and things like that, and so on and so on."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "26:53",
      "start": 1613.22,
      "text": "With, the closed source secure elements, just, just a high level thing, high level, summary. So secure elements, they become secure elements after a certification process, and this is very expensive, very time consuming. It can take a year or more, it can take a million dollars or more. and then in the end, in order to use these devices, you need to sign NDAs with, with the manufacturer, and then that severely limits what you can, expose. to the public, and so they wanna keep the code closed source to protect their, their IP."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "27:30",
      "start": 1649.94,
      "text": "and oftentimes the, these devices have low, specs, like you can't put a lot of code onto it, you can't, doesn't have high, low specs in terms of like memory basically, so you can't put a lot of code onto it. They have, of course, very high specs in terms of security, like physical security especially. but that said, there's an incentive, by the manufacturers to Hide bugs and hide vulnerabilities. And the reason for that is a lot of the, the cryptography that goes on in there is also at the hardware level. and so when bugs are found, and they have been found, it would require redesign of the chip, it would require recertification, new testing, so again, another year, another million dollars. And so there's high incentive for covering up bugs and hacks. and this is something I think is, so, That said, I think like the physical security mechanisms are, are great, we really should take advantage of them, but this fact that bugs, the, this disincentive, compared to users versus the manufacturers, I think is a, a, a big red flag, and it's something we in particular, try to avoid, and so that's why another reason why our code is open source, in particular, one of the most crucial aspects is the elliptical curve cryptography library, and As far as, is, as I'm aware, I think the Libsack P library on the Bitcoin Core, codebase is by far the best, most, most well-researched, most studied, really paying attention to side-channel attacks and so on and so on and so on, even, you know, the extensive testing that Peter's done, has led to, you know, bugs being found in OpenSSL and so on. So I think really when you're dealing with Bitcoin where if one mistake could be catastrophic Where you lose access to your funds, you really should do,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "29:30",
      "start": 1769.71,
      "text": "you know, the best, of course, and, in my opinion, the best would be using these, well vetted, well-researched open-source libraries. and so it's getting a bit long-winded, sorry. To go back into the- To go back into the, the secure element side. So we, we do have a, a secure chip on our device, and, we use that, solely for, authentication purposes, so unlocking the whole, the whole device. And so with that, we think, and we can get, again, get into details more, but with that, we think we can offer the best of both worlds in the sense of offering, you know, the physical protection enabled by secure chips, the authentication capabilities enabled by secure chips to protect your whole setup, yet still have, the security of, the functional security, again, these high level concepts that are hard to get right in Bitcoin, this functional security, in a transparent and, auditable way."
    },
    {
      "speaker": "stephan",
      "time": "30:26",
      "start": 1826.04,
      "text": "I was also keen to ask about backups. As you mentioned, there is this process with the BitBox 02 where you put in an SD card and the backup is created onto that. Is that an encrypted backup or is that an unencrypted backup?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "30:39",
      "start": 1838.87,
      "text": "I can chime in on that because I think, at first There's still the problem that people don't understand the, hierarchical deterministic wallet creation. When I go to conferences, I usually speak to kind of educated, skilled Bitcoin people, but still there's a high percentage of people not understanding that they can do a backup once at the beginning, and it covers their future received coins. This is just a concept that it's hard to get if you're used to like traditional time machine, wise backups. why can't I do a backup at the- Beginning and receive a coin in a year, and I, it's still covered by the backup I've done a year ago. This concept is so hard to understand and, and, and still people, there, there's still a lack of, big lack of education and, and then you present them, well, now you have to write down, twelve or twenty-four words. this is again hard to understand. Why do I have to write down words? what is that? Is that-- And it's really the, the education layer isn't made in a way where my mother or like people wanted to get into Bitcoin that aren't, that aren't computer experts can really get it. And I think we tried to defeat it a bit with, you just have an SD card. We tried to educate them directly within the app, and you put out the SD card that the backup has done. takes maybe a second and then- And you take out the SD card and st-stored it somewhere else. And, I think that concept is easier to understand rather than write down words, and then you need to hide them from visual sites and stuff. And, and at the beginning, we encrypted backups, but one of the most dramatic problems in Bitcoin key storage is not hackers and not co-not people stealing your coins, it's yourself, it's you losing passphrases. And I saw much, much more in, in, in- In, in the four digits amount of percentage, people losing coins because of losing passphrases, losing passwords, and the whole inheritance problem comes again into that, phase, and I, I think Protecting people from shooting in their own foot is way more important at the first place than kind of securing them. So if they, if they manage to lose passphrases quickly and easily, it's probably better to store, stuff by default unencrypted. the BitBox02 stores backups unencrypted by default, but gives an option to, to encrypt them."
    },
    {
      "speaker": "stephan",
      "time": "33:10",
      "start": 1990.49,
      "text": "Yeah, that's an interesting one because, yeah, obviously some of the more hardcore listeners will be probably perking up and saying, \"What? No, it should be encrypted.\" But I can, I can sort of appreciate here, there is also a user experience component that you're trying to manage as well, and that you have to consider both sides there as well."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "33:28",
      "start": 2007.76,
      "text": "If you, if you start to encrypt backups, what people do, I tell you, they start to write down the words, and then they think, \"Oh well, I'm going to store it in my, bank vault, right? So when I get on the bus, my wife can take my coins.\" Well, what do I do with the passphrase? \"Mm, okay, let, let me So then the question is, what's the purpose of the passphrase if it's like always stored? And then they think, oh, well, maybe I write the passphrase onto another piece of paper and give that to my, my lawyer or my notary. But then they're making security assumptions that aren't correct because if somebody, gets the passphrase and it's not secure enough and stuff, so it's, it's, it's dangerous, territory at all. So I think, a solution that's could solve that back up encrypted, multi-layer solution Is, what, what, what Pavel talked about, the Shamir secret. but in general, I think because we all saw more coins being lost at lost passphrases than at attacks, by default not encrypting is probably a good choice, but of course, we should ask more experienced users, \"Do you want to encrypt?\" Yes, and then they can choose, another factor."
    },
    {
      "speaker": "stephan",
      "time": "34:39",
      "start": 2079.17,
      "text": "Yeah, that's a fair comment, I think. And let's talk a little bit about the BitBox app. So, as I understand, now I had an- Opportunity to actually use the beta version of the BitBox 02 and, you know, you've downloaded the BitBox app and you, you know, you plug in and that's what you use to initialize the device. Can you tell us a little bit about that process? What's the BitBox app? How does that work?"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "35:02",
      "start": 2102.38,
      "text": "So the BitBox app, of course, is the, the user interface for using the BitBox, the BitBox 01 or the BitBox 02, that exists on your laptop, it's a, you know, the, the interface, to interact with the device, like, like all hardware wallet vendors have it. So the, the app itself, trying, trying to think of which, which level of depth to get into. I guess, one, one of the things, we use the app for with the BitBox 02, you may have noticed, is there's a pairing, that happens, during the setup process,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "35:43",
      "start": 2142.62,
      "text": "And this is, designed to,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "35:50",
      "start": 2150.31,
      "text": "at, at the moment, it's, basically binding the BitBox to your own computer. So we think this adds a bit extra security in the sense that if, suddenly someone replaced your app with a malicious app, or, replaced your BitBox with a, a counterfeit device, then this, this pairing code will pop up again, and it'll be an in Indication that, you know, something strange is happening. of course, we need to do-- we need to spend a bit more time on the UX to make that clear to users. that's one aspect. Another aspect is, prior to,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "36:31",
      "start": 2190.66,
      "text": "or actually, every time the BitBox 02 is plugged in, there's an attestation check. and so what this means is, well, the purpose of this is to try to, mitigate against supply chain attacks and counterfeit devices. And so the BitBox itself on the secure element, the secure chip, it's stored, a secret. And the BitBox will, or the BitBox app will send a challenge, the challenge gets signed by this, private key, and then, it gets the response from the, the chip, and then it can use, the same Bitcoin elliptical curve cryptography to try to verify, if the response is correct, if it matches the, what's, the public key. and, in that sense, you can get, some protection against counterfeit devices, evil maid attacks, and so"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "37:26",
      "start": 2246.01,
      "text": "on. yeah, maybe, to add to that is also that we, from the beginning, from the BitBox, oh one beta, we had, shipped it always with the native desktop application, because we kind of thought the browser environment isn't the right setup for doing, security crucial stuff. And I think that trend, is now something also competitors, will follow Flow because it somehow conceptually makes, way more sense also than if it comes to cross-platform, including smartphones, and usually you need to download, anyways something, on an app layer, to kind of bridge it with your USB stack or, kind of configure it. and I think the desktop app is just probably the ideal way how to communicate with the hardware wallets."
    },
    {
      "speaker": "stephan",
      "time": "38:19",
      "start": 2299.02,
      "text": "Right. Yeah, and I think it's, interesting because there's different philosophies and thoughts Thoughts around that, right? So for example, Trezor has a web wallet, Ledger has Ledger Live, which is a desktop application, and I think they've also got a mobile version. Coldcard doesn't even have an application, they just use, you know, Electrum or Wasabi, right? So everyone's kind of got slightly different ideas on that. I think the real kind of cyberpunk people out there, I think they'll appreciate that with the BitBox app, one thing I notice is it's kind of like, it's got the simple version of it, but if you want About that."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "38:53",
      "start": 2333.24,
      "text": "Yeah. I think, you know, this, there's still the big problem that, Horobolts are-- I mean, they cover security, but they don't cover privacy, or most of them, not cover privacy by default at least. And what privacy also means there's a little relation between privacy and security, because if you sacrifice privacy, you may reveal that you hold coins, which can, hurt your security. and simple answer could be the five dollar ranch attack, if somebody knows you're holding a lot of coins. So privacy is highly correlated with security, and most of the default settings of all horrible vendors are using, kind of giving up privacy by sharing the xPub or sharing, what they own in, in, in general, not sharing the private key, but sharing their finan-financial privacy. And, I think this is a crucial point, and we're working towards having a default option that your privacy is not, given up completely. But right now, what, or- since, since a year or two what the BitBox app offers is you can use your own, your own backend, and we also support Electrum Personal Server. it's still an expert-ish solution, but I think this is the best we currently can give to users that they can connect to, to their, to their own node and not giving up privacy and not trusting, central, validation."
    },
    {
      "speaker": "stephan",
      "time": "40:15",
      "start": 2414.96,
      "text": "Fantastic. Can you tell us a little bit about how the user might do that? Is there a specific software that they would use, or just literally just list the Port number or what?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "40:24",
      "start": 2423.88,
      "text": "Yeah, I mean, there's, there's documentation, but at the end, what they can do in the BitBox app, they can, change the link of the backend, and, if they wanna set up their own, validation and privacy stack, that means they need to install Bitcoin Core, and the easiest solution is, i-- to add Bit, Electrum personal server, This is a piece of software that's just a, a little layer that's not doing too much, and from then on, you have your own, Electrum server backend just for a single wallet or for a handful of wallets. because some other, mechanism would be that you install your own Electrum server, which is way over the top if you're only having a handful of wallets, because you basically index all the transactions that you can immediately access, all addresses, which is like ninety-nine percent of all the addresses you will never- ever use in your personal setting. And again, I mean, the whole concept with-- that's also a problem, when people use Bip thirty-nine, the mnemonic, which I, I still think has some flawed elements in, in, on the conceptual layer, because if you wanna restore, a Bip thirty-nine, seed, that means you either need to have a full-indexed, full-indexed, Bitcoin Core instance. Or you need to scan the whole chain, which makes it like needing a day for restoring a backup, and, the PEP thirty-nine somehow assumes you, you need to use central validation, which means you need to use, you need to give up privacy in order to restore a backup, unless you wanna run, a five hundred gigabyte system constantly indexing the whole chain, which again, I think backup isn't solved now, and, and that's also something we work on to make it, easy for you. Users to not give up privacy."
    },
    {
      "speaker": "stephan",
      "time": "42:14",
      "start": 2533.88,
      "text": "Right, yeah. And, as, as you were saying, with, it can be a little confusing and it's a little bit more technically involved to run EPS Electrum Personal Server, and then, not just that, you would have to do, the rescan command and then say, okay, when was this wallet started? And then it knows how far back in the chain to search so that you don't have to like search back five years ago when maybe you only started this wallet, you know, two months ago or whatever,"
    },
    {
      "speaker": "stephan",
      "time": "42:39",
      "start": 2559.08,
      "text": "right? Yeah I think the listeners will be very interested to discuss and know what your thoughts are is multisig. So what are your thoughts around multisig signature support? Do you agree that it's additive? Do you agree, do you want to try to see that in BitBox 02? What's your thoughts there?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "42:58",
      "start": 2578.35,
      "text": "Yeah, I mean, multisig is, is a very strong concept, how to kind of balance security. And, for sure there is need that user understand it better and users can use it. But it's, it's such a long road until it's doable by, non-experts. And as I said, I think the greatest risk currently is still the user itself. And with multisig, if you're, if you're not an expert, it's extremely complicated To do a setup, even with the best, user-centric applications, including Electrum and, and, and, and stuff, it's still very hard to set it up correctly, and it's so easy to lose coins, which makes me think, maybe- Maybe giving users an option now could be more harmful than it actually, it actually, achieves, security or better security. but for sure we wanna-- we're working on, on multisig solution, solutions, but it's still, you know, it's very immature on the concept level, and we wanna ship users something that's really easy to use and food, food gun safe, and, and this may take another, round until this is ready."
    },
    {
      "speaker": "stephan",
      "time": "44:15",
      "start": 2655.17,
      "text": "And I, I presume also, well, I know also that you can probably add some comments there around there are some difficulties as well with multi-signature if you were to, let's say, start with one sort of setup and then you might not be able to recover that in some other setup, right? Because it's not as standardized around things like what is the derivation path, what is the, what is the method, what was the script used. Can you comment a little bit on that, Jonas? I,"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "44:40",
      "start": 2679.82,
      "text": "I mean, it, it starts at the beginning. When do you, when, Participants. So how do you get their xPub? Do they send you an email? Do they give you a WhatsApp message? So you basically include Facebook in your trust layer, when you merge, a wallet? For sure, at some point you need to store the participants' xPubs or Pub keys on your hardware device, but how could you verify that this is actually the xPub of your, of your participant? And then do you need to always be physically present to sign a transaction? Do you need to plug in, USB sticks? Or, hardware wallets on the same computer, can you do it over the network remotely? And these are still, in my opinion, unsolved things or hard to solve, issues, which again has a lot of, a lot of, or a big surface, for attacks. And I think in order to give it to normal, non-expert users, there needs to be, done more work on that layer, on the conceptual layer."
    },
    {
      "speaker": "stephan",
      "time": "45:42",
      "start": 2741.99,
      "text": "Got it, I think that's a fair comment. Also, any thoughts around multi-signature with devices from other manufacturers as well? So do you have any thoughts on that?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "45:51",
      "start": 2751.12,
      "text": "Yes. Yeah, I mean, what we currently consider is also adding support for third-party hardware wallets into our, software stack. So of course, if you, if you, if you wanna store coins in the most secure way, you also wanna balance vendors. So if, if, if, if you can have, if your security relies on multiple vendors Vendors, it's more secure in general. So, I think that, that's something we, we should give to users and users should understand, but again, it needs to work perfectly fine and it needs to be, It needs to be aware of the risks that users screw up, which is still the highest risk."
    },
    {
      "speaker": "stephan",
      "time": "46:32",
      "start": 2791.56,
      "text": "Yeah, agreed. Okay, let's talk about PSBT, partially signed Bitcoin transactions. So, can you discuss around your thoughts on, do you want to work with PSBT or do you find it difficult to work with PSBT? I've heard differing opinions on that, so what's your view?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "46:50",
      "start": 2809.7,
      "text": "Yeah. I mean, PSBT is, is a very technical layer that shouldn't, or users shouldn't be aware of what PSB is in general, but since we are experts, and we are still on, on, on the tip of the iceberg in terms of usability, I think PSB is a very great piece of, of specification, and it's basically, you know, a file format, you can say, that includes everything you need to sign a transaction or to co-sign a transaction. And What people currently mean with PSBT on the user level is they can plug in an SD card or something and they can sign a transaction completely air-gapped offline. that's, that's something we, we wanna support in, in, or we consider to support in, in the BitBox because we have an SD card, we have the knowledge how to do that. It's just, you know, the, the demand and the layer of complexity for users are, are just, the demand is low and the complexity is high."
    },
    {
      "speaker": "stephan",
      "time": "47:49",
      "start": 2868.98,
      "text": "Okay, and while we're on that topic topic as well, I know it's not exactly PSBT, but in around this idea of airgapping, do you have any thoughts or what's your view around being able to initialize the device without touching a computer? So for example, the Coldcard has a function, something like that, where you can create it on the device and power it purely from a power bank. Did you have any thoughts on that with the BitBox 02? Yeah,"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "48:12",
      "start": 2891.93,
      "text": "yeah. Yeah, I, I mean, security is, as Pavel, from Satoshi Labs said, it's, it's very co"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "48:20",
      "start": 2900.42,
      "text": "Basically, it's a concept that you try to eliminate insecure channels. We consider USB an insecure channel because whatever comes from USB, we don't trust, we verify that on the device itself. But then people showed that you can actually, measure power on the USB stack and then figure out what people see on the screen. So every password you show on the screen might be insecure if somebody is accessing a side channel. So what mean airgap? Airgap means you take the device out of USB stack. And maybe add a battery to it, but then again, the battery, they could power analyze what you do, and then once you plug it in to charge it up on your computer or WiFi or whatever, they could send up, send out secrets. Obviously this, this is a more, hard, a harder attack to put through. But again, there's cameras. Cameras are also, collecting information, visual information in a large scale. audio signals, power signals, that can be-- power signals can also be captured from a battery source that's ten meters away. It's just a different, different security model you do when you air gap. It's probably a very good security model as long as it's, again, safe for users, not screwing, not screwing up. And, and with the BitBox, oh two, we have all the tool sets to do the, do air gap modes, but it's not currently supported, on the software, software side."
    },
    {
      "speaker": "stephan",
      "time": "49:48",
      "start": 2987.85,
      "text": "Got it. Oh, around change address verification. So my understanding here is, again, correct me if I'm wrong, you m-- you probably, you, you know this better than me, but, one concept there is that the hardware wallet has to know that it has the private key for that change address. can you talk to that, problem and how does the BitBox 02 make sure that it's, you know, doing that correctly?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "50:13",
      "start": 3013.14,
      "text": "I think this is a, a solved, issue for all the hard, hard wallets because it's, it's, it's a basic concept that you, if, if, if, if I send someone, bitcoins, I verify his address or her address, I'm, I'm sending, coins, towards. I'm not send- I'm not verifying where the change goes because mostly there's change But the hardware wallet always verifies that the change is something he has the private key, or is, is an address he has the private key, for, and, and therefore it's safe to, to kind of send the, the change, to myself. So this is, I, I'd say it's included in all hardware wallets because it's a basic need. The more complex problem is the fees, because you can verify the change is going to, to, back to myself, but you can't verify before SegWit that the fee was actually, correct or that you can verify the fee on the device, which an attacker could have misused to pay ex-ordinary high fees, but they, they wouldn't go to the hacker, they would go to the miners, so it's maybe not, not a large attack surface. Great. But that has also been solved with SegWit."
    },
    {
      "speaker": "stephan",
      "time": "51:27",
      "start": 3086.9,
      "text": "Okay, so let's talk a little bit around, the, can maybe the connection then with some other upcoming products. So I understand you've also got the BitBox Base. So can you tell us a little bit about that? What's the way that will all work together?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "51:41",
      "start": 3101.29,
      "text": "Yeah, so the, the BitBox Base, in my opinion, is a super great project, something I, personally work on since years to have this plug-and-play box. You can plug- And have the full verification and privacy stack on your own, because you know, if you run Bitcoin Core on your desktop computer, it works, but to be honest, it uses a lot of, or at least in initial block download, it uses a lot of resources. If you were, if you had shut down your computer for a couple of days, it again uses all the re-resources for, fetching the new blocks and verifying them. So it's, there's basically great opportunity to have a box Our little server, you can call it, running, next to your router that could all do, do the hard stuff for you and even do more when your computer, has been shut down. And, BitBox, BitBox Base is basically an appliance of, ready-to-use, platform, or even hardware device, people can plug in and have all the privacy and trust features they couldn't build their, themselves because of time or know-how resources."
    },
    {
      "speaker": "stephan",
      "time": "52:51",
      "start": 3170.8,
      "text": "Yeah. And then what is the way it's foreseen to work? Together, I presume you would buy a BitBox base and you would connect it to your, like, to your laptop, your computer somehow with the BitBox app, and then that way you've got the hardware wallet checking back against its own BitBox base, correct?"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "53:10",
      "start": 3190.04,
      "text": "Yeah. I mean, it's still, it's very, highly immature, project in terms of goals. There's a, a large area where we allow it for experiments, for users to defining, i-it's usefulness. But in general, it, it, it, it is, it is, it is a special computer that's optimized for, for Bitcoin and Lightning stuff. And it, it also has an included, hardware wallet, so there's a hardware wallet built into the BitBox. Space. There's a screen, you can really do, the same stuff you can do with traditional hardware wallets, but it also has, a kind of full-fledged, Linux computer. So basically, how the user story would look like, you, you, you plug your BitBox, BitBox Space into your, network, and it shows up on your app, you can connect to it, and then you, you trust your own layer, privacy is not, not violated, and you can do much more fun stuff, including Lightning, including- Push notifications when stuff changes in your environment. there's, there's a lot of possible features, probably way too many to not lose focus on doing the right things."
    },
    {
      "speaker": "stephan",
      "time": "54:21",
      "start": 3260.65,
      "text": "Great. And, let's talk about the mobile app as well. So, did you wanna just touch on what have you got planned for the mobile app and how will that connect up and how does that work with the rest of it?"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "54:32",
      "start": 3272.12,
      "text": "yeah. So the mobile app,"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "54:36",
      "start": 3276.48,
      "text": "we, we have a prototype working right now, so it's all working. What we're mainly working on is the, the UX, so, making sure that things that look okay on the desktop also look okay on the, the mobile, screen. and when we originally decided, what, what software stack to use for the desktop app, we specifically designed it to work with, both desktop and mobile. and so, Basically using the same exact codebase, which is, like a Go backend and then, typical, web frontend, HTML, CSS, JavaScript. we can take that and apply it in, in the different systems. And so the goal of the mobile app is for it to be as identical as possible to the desktop app, so you get the full features, on both. and then just, yeah, let-letting people, Use it as, as it would be used on the desktop."
    },
    {
      "speaker": "stephan",
      "time": "55:34",
      "start": 3334.12,
      "text": "Right, so literally they could be out on the fly with their mobile and plug in the BitBox 02, and off they go, they can do transactions with it. Yep,"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "55:40",
      "start": 3340.43,
      "text": "exactly. Like that. Yeah, maybe additional features that they can, you know, watch their funds on mobile, could also be on desktop. So there's kind of different use cases you could do on mobile."
    },
    {
      "speaker": "stephan",
      "time": "55:53",
      "start": 3352.63,
      "text": "Right. Yeah. So having like a watching only function, that sort of thing. Alright, well, I think those are some of the key questions that I had for you. Did you have anything else you wanted to touch on, Douglas or Jonas?"
    },
    {
      "speaker": "douglas_bakkum",
      "time": "56:04",
      "start": 3363.5,
      "text": "I guess, one of the, I was hoping to get into, I guess the, some of the security concepts, a little bit deeper of the, sure, let's do that. so, yeah, briefly, but, I mentioned ear-earlier that, we redesigned the security concepts of the, the BitBox 02, still taking the dual chip approach Differently. as I, I know in some of the past, podcast, they talked about different types of hacks against them. in particular, general-purpose microcontrollers, it's very easy to read out the secrets, from them. one example is, yeah, I guess in, in Russia right now, it's, legally accepted to be able to reverse engineer, software, including, firmware. And so for a few thousand dollars and, you know, Five, ten business days, you can send them a general purpose microcontroller, and they can read it off with microscopes and tell you all the bits and all the code and all your secrets that are stored on it, and so when we, when we designed our BitBox 02, we had this in mind, of course, a lot of other attacks in mind, and we're trying to figure out ways to kind of prevent all of these things. And so the, the concept then was, you know, of course, remote attacks, but also protect against someone physically stealing your device. And the idea there is that if someone does want to, does steal your device, they do wanna get to your secrets, make them have to reproduce, three different bits bits of information, plus, plus some more, but three main bits of information. One indeed would be, a secret stored on the microcontroller, the general-purpose microcontroller, but also make the, need to recover a secret stored on the secure chip. itself, which of course is designed specifically to prevent these Russian labs from extracting the secrets. And then the third one is just not have all of the information required to recreate the seed. On the BitBox itself. And so I think this is a bit unique for us in the sense that we, also use the, the user password, the user PIN, when you first enter into the device, and we cryptographically combine all of these, and then we use that as an encryption key to decrypt the seed. And so if you don't have, the readout of the microcontroller, you don't have the readout of the secure chip, and you also don't have the, or I should say it differently, you need the read The controller, you need a readout from the secure chip, and you also need, knowledge of what's, not on the device but in the head in order to recreate the seed. And so we think, with this, we can, you know, security in depth, I, I guess, is, You know, a good thing. And so try to provide as many different security layers as possible, and we have more than that, we'll try to write it up in a blog post. but try to provide as many, security layers as possible to try to make it as hard as possible for an attacker to get the funds."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "59:16",
      "start": 3555.51,
      "text": "I think one great additional, point is that the secure chip also allows us to, do measurements against, against brute forcing. that you can't offload it to a different system where you have much more CPU power It's always a problem, also a BIP thirty-nine problem, it's two forty-eight rounds that you, that it's made for, for, not very, efficient CPUs or, in the, in that case, MSUs. so we need to make, we, we needed to add measurements that you now can offload the other elements and then brute force it on a system where you have much more power. And I think that's something we achieved with, with the BitBox 02. And maybe one thing I, I'd like to add, for the closed source versus open source model, I mean, the closed source model is the model of obscurity, or- Probably can do an analogy to obscurity, and I think in the long run, there's always been examples that this model isn't the one that survives the long run. So, to just understand what the risks are, if, if, if, if you do, SECp256K signatures or ECDSA signatures on a, on a stack you can't control, there's always these nuances involved, like you need, either random, entropy Or you need, the, the R-RFC deterministic nonce, model. And when, by looking at the produced signature, you can't tell whether they have used, valid entropy, kind of, cryptographic, random number generation, or whether they have used the RFC standard to use a deterministic node, so they could use, something else, and you can't tell by looking at the signatures. So, and they could actually, export the private key mat or any secrets they could export through, clever uses of nounces, and nobody could verify that they're exporting, secrets, and they could just collect secrets by looking at the pub- Public blockchain, and it could have been done, nobody can verify them, so it's again a systemic risk. There could be, malicious nonce or signatures that extracts data on the blockchain and at some point somebody sweeps all the wallets. It's theoretically possible. That's why I think using closed source, is, is, is, is, is not a good concept, because- Again, the systemic risk, there's no security, experts that really can dig into those, things, and it could be time-triggered, you know, it could start to collect or exfiltrate information by date X, Y, Z, and I think this makes it, highly, highly complicated and highly risky."
    },
    {
      "speaker": "stephan",
      "time": "01:02:02",
      "start": 3722.96,
      "text": "Yeah, I think, actually, if I recall correctly, that is actually a point, Michael Flaxman raised as well, the chosen nonce attack as well. So that's, I presume that's, what you're referring"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:02:15",
      "start": 3735.12,
      "text": "But when you have open source, at least you can look at the code that does the SECp or the, ECDSA signature, you can verify the concept, what they are following is correct and even the code. While if you have secure elements that do the signature for you, you have no way to verify whether the concept in general is okay. You can verify the signatures and compare it to, kind of reconstruct the backups offline, offline, but then you, you don't know if there's time or user-based element that extracts only the In certain circumstances."
    },
    {
      "speaker": "stephan",
      "time": "01:02:46",
      "start": 3766.57,
      "text": "Yeah, I think, the listeners might get pretty scared about that idea, but, as you said, I think as you said, probably, like obviously there is a risk of theft and so on with hardware wallets, but I think it is a point that's well worth reiterating is that most people are likely to lose their coins by losing their seed or incorrectly doing the passphrase, those kinds of mistakes, than actually an attacker coming to get them. Now, that said, it could be that in five or ten years' time, the value if Bitcoin has gone Up so much, maybe at that point, you know, it, it does become more of an attacker risk than a lose your keys or screw up risk, right? Yeah,"
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:03:24",
      "start": 3804.67,
      "text": "yeah, hopefully. I mean, maybe to add to that, I, I still think hardware wallets are by far the, the best way for users to, securely, keep their Bitcoin safe. I mean, all these attacks or scenarios we just, pointed out are way more dangerous on hot stacks or on, on computers. They're using Python, libraries To sign ECDSA, which come from NMP or whatever, on secure source. So I think, by far HordeWallets give, non-expert users and including expert users the best security, currently."
    },
    {
      "speaker": "stephan",
      "time": "01:03:59",
      "start": 3839.57,
      "text": "And also actually one thing I noticed is you guys are having a Bitcoin-only version. Tell us about that. Go for Jonas."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:04:06",
      "start": 3846.93,
      "text": "Yeah, I advocated for Bitcoin-only a long time ago. But I, I, yes, as politicals say, politic-- politicians political say, there is Bitcoin and there is shit coins. And, I think Pavel also, said a good point that, you know, without altcoins, they would have not survived seventeen and eighteen, which is probably true point. And there was also the argument of bringing people on, on board and transitioning them into Bitcoin at some point. I mildly agree with that, not fully, because for me it always also feels a bit about, you know, helping people to getting scammed. so I think it's, there's, it's, it's, it's not an easy line you need to draw at some point, because do you want to support coins that obviously look after a scam? And then where, where, where, where you draw the line between what, what is a scam and what not? I personally think there is Bitcoin and there is shitcoins, and I think we shouldn't, if users think that way as well, we shouldn't hurt them additionally by adding risks of having firmware that it's supposed to do stuff in shitcoins. Yeah. and, that's why, why we have a Bitcoin only version. It, it's, it's, it's made for, for users only wanting to use Bitcoin, and it has a reduced, reduced, attack surfa-surface, and it's also signal, that they want Bitcoin only. It's also like, you know, helps us to, know what to do in, in the future."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "01:05:48",
      "start": 3948.09,
      "text": "Yeah. So, so just to re-emphasize, the whole, the whole point of having a Bitcoin only version is to reduce the- Attack vector. So every new coin you add, every new function you add, U2F for example, it allows different, communication protocols to come in, and they use different cryptography, so there could be, issues in the cryptography itself, issues in the API call and things like that. And of course, the simpler you can make it, the more secure it, it can be. and so that, that's the whole point, of that. And so a, an important note is that our- the addition, the Bitcoin only addition will never be able to, allow, firmware from the standard addition, so it'll never be able to, you, you cannot switch the firmware between them, and that's also of course, a mitigation against, increasing the attack vectors."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:06:42",
      "start": 4002.0,
      "text": "Yeah. Just to add here, it, it, it sounds after we're, we're, we're trying to, make people buy, two devices, but actually it's not that, it's, it's, it's for security precaution Be- because, you want to eliminate that an attacker can exchange, your device or can replace the firmware by the insecure one, once they found the bug in the, in the non-bit-only, Bitcoin-only version, they could replace firmware. So it's actually the device can only load Bitcoin-only firmware, which makes it more secure, that it can't be replaced by, stuff that has been broken."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "01:07:16",
      "start": 4036.19,
      "text": "Yeah. And so, and that said, since we're, we are a for-profit company, of course, we wanna pay- Our employees' salaries, and we wanna, you know, live up our mission to, improving the whole, the whole ecosystem, then it is important for us of course to listen to the market, and, in order to, to- set our, our product, product goals. the market did tell us they want Bitcoin only wallets, but of course, another part says they want, to be able to explore other coins, and so we're trying to, trying to figure out what, what the best approach is and, and move forward and listen to our users."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:07:52",
      "start": 4072.45,
      "text": "Yeah, and we, we never forget that we are, we are a Swiss based company, so Switzerland is, is, is, is kind of the, the land of neutrality. We also want to give user power and not, not when, when someone wants to use an altcoin, our mentality is more, well, we educate them, we inform them, but if they wanna use it, it's their decision because neutrality is, is important. It should also underline that we are, we're, we're producing everything in Switzerland. It's a very crypto friendly environment. There's less risks of being intruded by, by agencies that we need to follow certain policies. The supply chain attack is reduced. It's produced really in Switzerland. And programmed in Switzerland, so I think this, this is also a benefit that will, at some point come to users, to the users, yeah."
    },
    {
      "speaker": "stephan",
      "time": "01:08:48",
      "start": 4128.12,
      "text": "Alright, that's great. So, look, I think that's all, all the questions I had. So, let's, just before we let you go, make sure you tell the listeners where they can find you online and, where they can go to find Shift Cryptosecurity online."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "01:09:02",
      "start": 4142.45,
      "text": "Yep. So, the best place to go is our website, so shift- Crypto dot ch, and at the bottom you'll find links to our, different accounts on Twitter and Medium and whatnot, and of course Jonas is on quite, quite widely fol-followed on Twitter, so you can find more about there, and, I'm getting on Twitter myself also more and more."
    },
    {
      "speaker": "jonas_schnelli",
      "time": "01:09:26",
      "start": 4166.31,
      "text": "Yeah, I think Twitter is always a good medium if you wanna get more information. There's, Shift Crypto HQ and myself, Jonas Schnelli, to contact if you have any questions. Of course, IRC and all the other channels work as well."
    },
    {
      "speaker": "stephan",
      "time": "01:09:40",
      "start": 4180.84,
      "text": "Great. Well, look, Jonas and Douglas, thank you for joining me today."
    },
    {
      "speaker": "douglas_bakkum",
      "time": "01:09:44",
      "start": 4184.86,
      "text": "Yeah, thank you very much. It's a pleasure. Thanks, Stefan, for having us."
    },
    {
      "speaker": "stephan",
      "time": "01:09:48",
      "start": 4188.92,
      "text": "So now you've had a chance to hear from some of the different major Bitcoin hardware wallet vendors, and they've got different product offerings with slightly different philosophies and ways of crafting their product and service. I have one more episode to come in this hardware wallet series, so keep an eye out for that early next week, and that is with Justin Moon and Stepan Snigirev. Just a quick reminder about some conferences that I'm attending coming up. There is Baltic Honey Badger 2019. The website for that is b h two thousand nineteen dot huddlehuddle dot com. I'll be emceeing a panel on Lightning there, so if you're around, it'd be great to see you guys there. And also, there is the Lightning Conference where I will be one of the MCs. So the website there is the lightningconference dot com. That is in October. It's in Berlin. So, yeah, if you're a listener, I'd love to meet you guys. So make sure if you see me around there, come and say hi. As always, the show notes, And also the transcript are on my website stephanlivera dot com. As always, thanks for listening, and I will see you in the Citadelles."
    }
  ]
}
