{
  "episodeId": "SLP107",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "jeremy_welch_jameson_lopp": {
      "name": "Jeremy Welch & Jameson Lopp",
      "role": "guest",
      "tag": "JEREMY"
    },
    "guest_2": {
      "name": "Guest 2",
      "role": "guest",
      "tag": "GUEST"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:08",
      "start": 7.81,
      "text": "Hi and welcome to the Stefan Livera podcast focused on Bitcoin and Austrian economics. Today for episode 107, we are talking with Jeremy Welch and Jameson Lopp of Casa. But first, let me introduce the sponsors of the podcast. Check out Kraken, one of the world's leading Bitcoin exchanges. I'm really impressed with the way they have operated consistently with a strong Focus on security over the years, they have acted ethically in the space as well under Jesse Powell's leadership. They're one of the longest standing Bitcoin exchanges, and they consistently rate the best. They've got high trading volume and low fees, with no minimum or hidden fees. Kraken also have twenty four seven support, and on the institutional and business solutions side, they are providing best in class accounting, reconciliation, and reporting services for cryptocurrency hedge funds, asset managers, and fund administrators. Kraken have an OTC C desk for those higher touch, large block trades. They offer five fiat currencies and also offer margin and futures trading. To learn more and sign up, go to the Kraken link in the show notes. Next up is Unchained Capital. They're doing Bitcoin financial services, and their two main products are a two of three keys multi-signature vault and a Bitcoin collateralized loan. So with the vault, remember it's difficult to use multi-signature right now, but Unchained Capital have a very easy solution, and you can use Trezor or Ledger wallets, and you're still maintaining control with your two keys, and you can distribute those keys to improve your security a little bit. And we'll also be talking with Drew Bansal from Unchained Capital on the podcast shortly. So keep an eye out for that episode. Remember, Unchain Capital also offer Bitcoin collateralized loans, so you can get USD liquidity without selling your bitcoins and incurring that capital gains event, which might be better for you from a tax point of view. So they store that under a dedicated multisig address under collaborative custody. So if you wanna learn more and sign up, go to the Unchain Capital link in the show notes. So for this episode today, we are carrying on with the Bitcoin custody series, and this episode Episode was actually recorded to, together in person at Riga just before the Baltic Honey Badger Conference, the first day. So we're speaking with Jeremy Welch, the CEO of Casa, and Jameson Lopp, the CTO of Casa. Now, they've both been on the show previously. Jeremy was on SLP twenty-six and Jameson was on SLP forty-three. So keep an eye out for this conversation where we're talking about some of the different security decisions made from Casa's perspective and how they have designed their diff- different services and how they're thinking about security, which they have recently released in the Casa Wealth Security Protocol document. Here is the interview. Jeremy and Jameson, welcome back to the show. It's fun. How are you, man? Good. Great to be here. So, we are recording here in Riga, just before the Baltic Honey Badger 2019. So, yeah, look, guys, I wanted to get you guys back on and talk about the Casa security or Casa Wealth Protocol rather, and also just, you know, what's going on with Casa these days. So, Maybe, Jeremy, you just wanna just give a quick overview on where the company's at and what's going on? Sure, sure, sure."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "03:23",
      "start": 202.7,
      "text": "So, just, just this past week, we, or, or about a week ago, we, we released this Casa Wealth security protocol. we've had, we've had some other updates around the, the multisig side and also around SatsApp and around, some updates to the node. but the, one of the biggest things we've done in the last few weeks is released this document that really"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "03:47",
      "start": 226.59,
      "text": "features that we chose, we actually chose to go ahead and, and elucidate all of the features that we didn't choose to use too, because there are specific reasons why we did those, and, this should just help. There's a lot that we usually walk our clients through. Anyone that comes to us, they, most of our clients actually know all the, the things that are in this doc, already, but for the kind of majority of the population Majority of the, the Bitcoin community, they're not aware of this, and we, we just thought that putting in a document form, making it really easy to access, and then also update, and as we learn, as we work with customers, you know, we'll update this from year to year, but it makes it really easy to kind of have a, have a, a, a kind of rule set to, to really, kind of gauge against, so."
    },
    {
      "speaker": "guest_2",
      "time": "04:32",
      "start": 271.9,
      "text": "Yeah, I mean, this is part of what I think is like the real value add of Casa as a system, where we've focused a lot on both the technical and the like user interface design, such that a user could just come into Casa and start using it and basically have this huge benefit of the wealth of knowledge of like fifty pages of, of, you know, technical decisions that have been made around the security model. But of course, we have people Who are securing a large amount of wealth, within our system, and in many cases, they want to then further dig down into actually understanding, why the system is designed the way that it is. And this, like Jeremy said, basically explains those decisions that we've already had to, describe to a lot of our customers over the past couple years. Fantastic."
    },
    {
      "speaker": "stephan",
      "time": "05:24",
      "start": 323.65,
      "text": "Yeah. And I've, I've had a chance to read through the document. I thought it was really nicely written. in the document, you speak through the three- Alternatives, right? So you've got kind of do-it-yourself custodial storage and then other commercial sovereign storage systems. And another thing that struck out to me is also just the comparison with Glacia protocol. So my previous interview was with Diogo Monico, the maintainer of Glacia protocol, and it, it strikes me like as I was reading the document, the Casa document, it's essentially talking about how there are certain trade-offs that we make using Glacia protocol. I think one of the key ones Is the difficulty of usability and the difficulty of setting up, and I think that's one thing that I view Casa is doing is, you guys are really helping with the usability of, high security option."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "06:13",
      "start": 372.64,
      "text": "Do you wanna discuss about that? Sure. so w- this, you know, everything we built around the Casa Wealth security protocol, is in direct response to and is, kind of a, an extension of learnings from Glacier Protocol. so Jacob Lyles, who created the Glacier Protocol, is on the team, helped us write the- This document helped us really pull a lot of the resources together whenever we first built this, but we used, we actually used Glacier Protocol as a kind of, basis to, to start working from, and a lot of companies have done this in the past. A lot of, even exchange companies used Glacier Protocol early on as foundations for their cold storage, and we just saw that, that it was, you know, i-i-it's rock solid, but it, it's very hard to, to implement and execute and set up, where we wanted something that, you know, Core threats, and we've kind of identified these, these thirteen core threats. One of them is, you know, just, just working from like what we call a child or pet attack or these kind of usability issues of needing to be kind of, idiot-proof in a sense, right? And Glacier Protocol is just really extensive, and so from that perspective, it does, it will always sit-- We, we actually are, I don't think we've announced that publicly yet, that we are kind of co-maintaining with Diogo and, and, and those guys with Glacier Protocol, but we, we kind of did the learning from there, and then we've tried to extend it, and specifically in the direction of where, you know, the, the Anchorage guys, and they built a phenomenal product, phenomenal company, and, they're really focused on the enterprise side, we're kind of extending in the side of the consumer and the side of the individual, small teams, for kind of maximum security, and we, we talk wealth security instead of just Bitcoin, because Bitcoin is the core focus, and that is around, you know, Bitcoin as data and, and these threats are gonna be true of any type of data kind of going forward and kind of personal wealth. But"
    },
    {
      "speaker": "guest_2",
      "time": "08:07",
      "start": 486.71,
      "text": "I think that you could potentially describe Casa as seeking to find the optimal practical security solution. when it comes to security, if you're, if you're really trying to go for like fully trustless, fully, minimizing the risk of anything going wrong, then You take it to the extreme, you basically can get to the point of, well, you basically need to be writing your own software or at least auditing all the software you're using, and, and then even the more extreme is, well, on the hardware side, you basically need to be like fabricating your own hardware to make sure that nobody has tampered with it, 'cause I mean, you know, we're, we're at the level of complexity these days with the hardware that nobody really knows everything that's going on, and so the, the, the question is, like, you know, Assume that everything below this level is working and can be trusted, and, and for us, we're, we're kind of raising the line a lot higher and saying, well, you know, we are, we're gonna assume that, you know, if we spread out- Your, your key generation and, and management across like multiple different providers, then you're, you're lowering the risk to a point that you don't really need to worry about things like supply chain attacks or low-level hardware issues."
    },
    {
      "speaker": "stephan",
      "time": "09:28",
      "start": 568.45,
      "text": "Yeah. And to me, even reading the wealth protocol, wealth security protocol document, it came clear to me there was this concept of defense in depth, right? It's saying, how do you set up your security in such a way that any individual failure- Will not compromise you totally, that you can afford one failure or before you lose your wealth. You"
    },
    {
      "speaker": "guest_2",
      "time": "09:51",
      "start": 590.9,
      "text": "need to have a, a more flexible system because, Bitcoin and the sovereignty that it gives to you is also, highly inflexible and unforgiving when it comes to mistakes, and, and that's why it seems like the bigger risk of loss in these systems is actually due to ignorance and user mistakes. as opposed to actual attack and theft."
    },
    {
      "speaker": "stephan",
      "time": "10:17",
      "start": 616.64,
      "text": "Right, yeah. So there's that idea that you're more likely to screw yourself out of your own coins if you're trying to do multi-sig and you make a mistake with it. I think even Andrew Chow on the previous episode mentioned that he had difficulties trying to get multi-signature with multi-hardware wallets working, and he is himself a quite competent technical developer. So if it's hard for him, it's, you know, it's gonna be hard for anyone, right? So, there's definitely some components around that. Let's talk a bit"
    },
    {
      "speaker": "stephan",
      "time": "10:44",
      "start": 643.6,
      "text": "Document, so you've got here, minimal knowledge."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "10:47",
      "start": 646.88,
      "text": "Yeah, and it's, there's a lot around minimizing data, on Casa. It's both the, the, the for privacy reasons, but also for can't be evil reasons, right? That's one of our kind of core company principles. but we have a set of system design principles. And anybody, we're, you know, we're, we're touching on a few things from the document. Anybody can go download this. You just Google, Casa Wealth Security Protocol, or I think"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "11:12",
      "start": 671.74,
      "text": "it And that's what the-- But you can, yeah, you can, you can, you can check this out and, and kind of, follow along, but we-- There's a lot more here, but kind of the high level there is that, Elena has this term from, that's, you know, don't collect what you can't protect. And for most companies, most, you know, even just from the, the side of people exploiting it for their own purposes, this can't be evil principle is what we're talking about there. You need to minimize data, so minimal knowledge just really means that we're gonna have minimal knowledge overall of, of data, period. and usability as security is another one. just thinking about export support, it's not just about even like the software, it is about the integrations of Humans and humans being part of that system too and having experts, sovereignty as a principle, incentive alignment, again, that kind of aligns with campy evil. If we can't even attack you or an internal, employee can't even attack you, then that just changes the logic tremendously. If the data's not even there, it changes the logic tremendously versus if a, kind of internal employee, Is gonna have to be tested regularly whether they want to exploit, data. So like keeping, keeping those system design principles and then looking at the total number of threats, and we had about thirteen total threats, that we consider, is, is how we then chose the, the kind of selected features."
    },
    {
      "speaker": "stephan",
      "time": "12:36",
      "start": 756.11,
      "text": "Yeah, a-and there's also the principle of usability is security. So, did you wanna touch on that around how, i-in making it more usable, you actually are making people more secure? So, quick example. I think it's probably fair to say a lot of people have looked at Glacia, but have not executed Glacia, because it takes a certain level of patience, diligence to execute, and I think that is a key point from Casa the way."
    },
    {
      "speaker": "guest_2",
      "time": "13:02",
      "start": 781.57,
      "text": "Well, and, and basically every step that you have to take is a potential mistake. So, you know, the simpler you can make it, the more-- wh-when I think of usability, I think of, when we're building actual software interfaces that humans are using, you are creating a series of paths that a user can go through. And at Casa, we're trying to limit it to paths that include the best practices that- include a lot of these, security principles so that what you're really doing is you are trying to throw away as many footguns as possible, you know, wi-within the like infinite number of possible decisions that a user could make when they're setting up and, and executing their own storage, so many of these, of paths Make it possible for you to, screw up in a catastrophic way, and we're basically just trying to, you know, create guardrails that prevent the user from even going off onto those paths in the first place,"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "14:11",
      "start": 850.92,
      "text": "while still maintaining the sovereignty. That was like an important point, and that's why this kind of full system design principles, you have to keep them in balance, and it really is, it, it really does have to be balanced because there are certain things you can do to improve usability, but that take away control from the end user going fully centralized. It's way more usable. I mean, let's be frank, it's just, you know, Coinbase and just throwing someone a regular login is way more usable on the surface, but it immediately takes away sovereignty, immediately takes away control, it immediately creates a can't-be-evil situation to where, you know, someone could take coins, and so doing that balance of making sure it's usable while at the a- absolute extreme that we can, while also maintaining that sovereignty is really important while minimizing data, and we've, we've even gone as far even from the legal structure structure of the company, the, we have this, open data policy, our privacy policy, we kind of wrote a totally new type of privacy policy, and, and that's open source, other companies can copy that, but we're trying to go through kind of every step of the way to build up this stack, in terms of the design of the overall system and the incentives even for the internal employees to, again, a-address these thirteen threats."
    },
    {
      "speaker": "stephan",
      "time": "15:24",
      "start": 924.31,
      "text": "Let's talk a little bit about some of the, I guess, what are some of the big threats in your mind? What were some of the ones that are most obvious, for the user? So, I, I guess, just off the, yeah, off the list here, there's a few SIM hijacking, that's a big one lately, Supply chain attack, that's something where, you know, ever- a lot of people are concerned about that and trying to have different hardware wallets and different, software that they're working with, data credential loss, Or even, being attacked on your, the platform that you're using. Did you have anything that you wanted to kind of highlight?"
    },
    {
      "speaker": "guest_2",
      "time": "16:00",
      "start": 959.96,
      "text": "Well, I mean, I think that of the ones that are listed, you know, the, the most common one is just simple data loss. And so that's why we believe having, you know, a geographically distributed set of- Hardware devices that are easy for the user to visualize and think about, you know, how are these actually, distributed? That gives you a level of redundancy and robustness that is gonna exceed, you know, ninety-nine percent of other people who are just keeping all their keys in one place."
    },
    {
      "speaker": "stephan",
      "time": "16:32",
      "start": 991.7,
      "text": "Right. I, and I suppose let's just for-- I think most listeners might have, you know, heard the earlier episodes, but just for the, in case they haven't, the basic overview, you've got the, the silver and gold. Which is the two of three basic multisig, and my understanding there is they have one hardware wallet, and they've got one key on their phone, and then one key is the Casa recovery key in that model. And then taking it up a notch to the, is it platinum and diamond, and that is the eighteen hundred dollar level and the five thousand dollar level, they-- that is a three of five setup. We have three hardware wallets in that model. There is one key held on the user's- Mobile phone, and the fifth key is held by, is the Casa recovery key. so I guess let's just talk to m-maybe the two of three model. I think one concern I've heard from Bitcoiners is that, oh, hang on, does Casa have two of my three keys? Two of the three keys? How, how can I be sure that I hold, you know, two of three?"
    },
    {
      "speaker": "guest_2",
      "time": "17:39",
      "start": 1059.19,
      "text": "Well, you can be sure that you hold two of three. We, we also have, export functionality, on the mobile key. I suppose, however, it's impossible to prove that Casa doesn't have, the mobile key. that is one thing that, you know, you'd have to quote-unquote trust us on. Right. And so, you know, this is another good reason of why, you know, there are trade-offs here. you know, we do intend to add ability to have two different hardware devices so you could then have a Assurance that you have two of the keys and there's no way Casa could have two of the three. but right now, that assurance is best provided by the, the three of five model."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "18:20",
      "start": 1100.13,
      "text": "And we, we kind of rolled this out intentionally, from the three of five where we were able to, build up a user base and work directly with clients. We have direct client relationships, it is kind of like a private banking relationship. We learn a lot from client preferences. We've done a tremendous amount of testing before we rolled it out to people publicly, but then we also learned a ton from even just the first several months and, we're now, over a year of- Being public, it's, I guess, it's almost like one point five years of, of being public, and all of that, that wealth of knowledge, we've kind of scaled up, we always intended to, to scale, and we actually have a, a single key, a mobile key as well, that's, that, it's just, again, it's, it's a, it's a single key, it's on the phone, that's actually used in a, it's the same key that's shared with our Sats app. So, Started with the three of five most premium multisig, and then we slowly rolled out. We had two of three, we had the single key, slowly rolled those out. we rolled out the two of three specifically to gold customers first, to make sure that that was usable. We also, you know, we mentioned before the multi-location, multi-device, multisig model, the reason around that, again, is in terms of these thirteen threats, that model is what mitigates those threats the best. And the-- there's a weird, trade-off, where- With the mobile device, if you're going to use a mobile device, from the principle of the usability side, you actually wanna maximize usage as soon as you decide to even use it, because of the fact that you can also maximize kind of usability. now that mobile device As a single device, is your phone is potentially connected to, the internet. we do have customers that choose to keep that off at all times, never really connect to the internet, and that effectively does act similarly to a hardware wallet, but it is effectively just a really fancy hardware wallet. but we, you know, for most people, they keep it as a regular key. And people have asked us about that question too, and what, what that comes down to is that, you know, i-it's also true that Apple or Google and most, you know that people are using, you know, they could even try to exploit that key. A-and as soon as you put that key on the platform, you wanna maximize the features that are available there. So we've done that now on the phone, and for the two of three, it's specifically designed, it's not designed to hold millions of dollars. it is designed to hold somewhere between, say, a thousand dollars and around a hundred thousand, sometimes less. We do have people that, you know, put even a little less than a hundred thousand dollars on the three of five, Range of what people are comfortable with, but, it is designed to, to be an entry level version of like just getting, getting started with multisig. That's why we decided, hey, let's, you know, we will, we will use the, mobile key and one hardware wallet. And for most people that had started using this, they'd never used multisig before, so it was already a learning experience. We had a lot of people that upgraded immediately after, and they were like, \"Oh, yeah, I get it now, why there need to Wanted heavy testing around just that, that single version first before we, before we do that. But, you know, these are, these are great questions and, the community's been, is always phenomenal about, about asking and figuring out these, these kind of, nooks and crannies of questions. And again, that's why we released this document, is that there's a lot more even beyond some of these questions that, that customers are asking. And so we just wanna, kind of constantly put these forward and bring these for ourselves and have that level of transparency We expect to get a lot more of these questions."
    },
    {
      "speaker": "stephan",
      "time": "22:10",
      "start": 1330.24,
      "text": "Yeah, sure. And I think it might be good just for the listeners who aren't familiar just to understand what is the way the mechanism works. So they might be thinking, \"Oh, do I need to bring all three keys into one place at one time?\" But actually, it's more like you individually do the signatures. Do you wanna just talk through the process?"
    },
    {
      "speaker": "guest_2",
      "time": "22:31",
      "start": 1350.79,
      "text": "Yeah, so, you know, when you're creating a transaction with the Key Master app Actually initializing is like any other transaction, you can scan a QR code, you can manually input data, but, basically you, you set those initial details of the amount and, and the output destination, and then you'll apply your initial signature there with the key that's on the device, and, you know, most likely, like you're using either, you know, biometric or face ID or, or PIN input to basically unlock, the mobile device so that you can access, the key. Which we keep secured, via the secure hardware elements that are on the, phone. And so then what you have is a partially signed transaction. It's not valid for broadcasting on the Bitcoin network. You then have to go figure out, you know, what other devices do I want to use to add a sufficient number of signatures that it becomes valid. And, and essentially you just, you know, tap within the app on the device you want to use, and you say, \"Hey, I want to add another signature from here.\" Will then, you know, generate, a short lived, unique link that you can use to essentially go find that device wherever it is, plug it into a laptop, click on the link, add the signature, and then continue that process until everything is done. And of course, it can get more complicated if you've lost de-devices and need to have, help from Casa, that, that enters into a different, you know, logical like recovery process. But, under normal circumstances, you're basically just going to be traveling around, getting enough hardware devices that you can reach that threshold. And The, you know, the other thing about making this a really usable system is that we also have health checks available. We have the ability for the user to essentially do key rotations and swap out devices that get lost or broken or compromised without even having to reach out to Casa for help. It's just a simple wizard that you can walk through within the app."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "24:38",
      "start": 1478.07,
      "text": "And this ties into, you know, even more of a reason to use the mobile device, is that we realize that people, people carry their mobile devices with them everywhere and out of any, y-y, you know, arguably sometimes even more than a, a birth certificate or a social security card or, you know, government ID, people keep track of their phones always on their person. and whether it's Candy Crush data or, some, you know, maybe it's a favorite photo or something, they're, they're valuable, it's data valuables that are already Phones and people treat them, very personally, and they, they, they protect those devices. and, and, and from that side, you know, people usually have it on them, and so if, if they're traveling from one location, say it's a home, to an office or to a, this, you know, third location that could be even in a different city, they're gonna have their phone on them, they're gonna use that as a communication tool, and so using that as the guide tool to be totally asynchronous and sign, you could go, you could The, the first one on one day, go two or three days later if you wanted to in a totally different city and signing, and then you've, you've maintained the distance between those two signings, and within that time span, that also means an attacker has to maintain that distance. it is true that an attacker could hold you at gunpoint or do something, more aggressive, but even in that case, they're still gonna have to tran-- you know, go, go these distances, and the more time that's, you know, we're just raising The bar there, the more time that's required to go these distances and, the more people, the more places you have to go, the higher likelihood that someone gets caught, someone gets noticed, you could, you know, whether it's, actually kind of saying safe words, and we even have like, that's part of our service around this, is we even have safe words and specific process and emergency lockdown buttons and all these other features that are built in, but it comes to that usability of having the asynchronous nature where you can go different places, but having Is kind of seeing the command center kind of on the, on the phone?"
    },
    {
      "speaker": "stephan",
      "time": "26:41",
      "start": 1601.04,
      "text": "Yeah, I think that's the other thing as well that maybe might not be apparent that, a customer can sign up in a more pseudonymous way. Can you talk to that?"
    },
    {
      "speaker": "guest_2",
      "time": "26:52",
      "start": 1611.59,
      "text": "Sure. So, you know, at Casa we aren't a, a bank or a financial institution, we're a software service provider. within the context of actually managing keys, Casa only ha- ever has one out of n of your key set, and, and those keys are always kept completely offline and requires, you know, manual human, recovery process to be gone through, usually a process that take, can take multiple days. this is also- So, you know, configurable by each user and, and how they want that to be done on the Casa side. But, the, the, the general gist of it is that, Casa is, is going to be helping the user help themselves, is, is the best way that I know how to put it. the- The downside to this is that, you know, whenever you're into a situation where you aren't taking the time or don't have the level of knowledge that you can do everything all by yourself without asking anyone for help, obviously that's gonna be the best privacy. But if you want to save time, if you want to have expert guidance, then there has to be some sort of communication, there has to be at least some sort of, you know, pseudonymous email address or other communication, endpoint for- Us to, to have back and forth. So while we are not a financial institution, we don't do AMLKYC, we don't actually care about your government identity, we do need to have some way to communicate with you in case something goes wrong, you know, if, like Jeremy said, if you hit the emergency lockdown and we basically refuse to, to allow any signatures to be added for anything, then you'll need to go through a process, in order for us to unfreeze the account or- Or if you, if you lose a sufficient number of devices that you need Casa to, to dig, the cold storage key out and, and sign it, you'll need to go through additional processes because at that point, if we believe that you may have been compromised, you know, we need to ask for some other- You know, non-identifying questions, but, but some sort of authentication questions, whether it's, you know, things that you know, special phrases or words, or even, you know, photos of, of either yourself or o-objects or, you know, it's basically any type of unique identifiers that, that you are comfortable with using that would be difficult, if not impossible, for an attacker to replicate."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "29:27",
      "start": 1766.66,
      "text": "And our, our lawyers, I'll, I'll, I'll throw out there that, you know, a lot of times, especially around products, you don't So the lawyers did a really great job of innovating here, but, we really did, have a phenomenal amount of help from, from Gunderson and a few other lawyers, law firms that really helped us, and we spent a lot of money thinking through what, what's the minimal a-d-a- amount of data that we can capture that would still be serviceable, still be, you know, would still match up with any legal requirements in terms of the terms of service and our ability to provide a service, but without needing additional data that could become potentially explo and from that end, you know, we do, we do have a photo verification feature, but you could take a photo of a cup or something else, right, that you're, that you're gonna use as, \"Hey, like it's still me.\" You don't have to take a photo of yourself. All those photos are, are locked down and, are, and, you know, internally we have a ton of, this is totally separate, but we have a ton of practices around key signing, code signing, commit signing, but we also, lock down those photos and the data infor- or the information on the customers is also all encrypted separately, and, and so even accessing that information is really hard internally from the limited information that we have, but we, we did kind of reach this, a-and that's why we published the open because we reached this kind of what we found to be a totally new level of what could be possible as a company to operate and still respect that sovereignty, and, and, and kind of respect the privacy of the end user."
    },
    {
      "speaker": "stephan",
      "time": "30:58",
      "start": 1857.71,
      "text": "Yeah, I mean, that's a great focus. I think, The next question is something that most people don't wanna think about, but it's something we do have to think about. It's inheritance planning. It's many people who are Bitcoiners, they irrationally we just think, \"Hey, I'm gonna live forever.\" But how is Casa thinking about that in terms of passing it on for that person's family or heirs? Yeah, I"
    },
    {
      "speaker": "guest_2",
      "time": "31:21",
      "start": 1881.0,
      "text": "mean, that's actually an entirely separate project. I think we briefly touch on it here, but, you know, we're- We're eventually going to be having probably a very similar document like, like the wealth security protocol, except it is specific to inheritance. I mean, we,"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "31:39",
      "start": 1898.77,
      "text": "we do have, I mean, it's like, we, we haven't talked about this publicly, yet, and that's actually the reason why we even, why, why we approached Jacob in the first place was not actually directly around our protocol, but we were like, \"Look, like, you know, you've built Glacier Protocol, he was an old friend of mine, and we've learned a ton from this,"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "31:59",
      "start": 1919.42,
      "text": "All that we've not really announced publicly, I guess it's out there now. but we do have an inheritance protocol, and similar to the document that you see here, we are mapping this out and we've been testing it, and w- you, you know, you can dive into, to more of the details, but I, you know, I guess we should just, if we're gonna address the question, we should probably just talk about it,"
    },
    {
      "speaker": "guest_2",
      "time": "32:18",
      "start": 1937.92,
      "text": "right? Straight up that we have this. Right. I mean, it's a, it's a similar, type of We can leverage the, traditional inheritance processes to be more compatible with these new, you know, technologically sophisticated, sovereign setups. And so the- I guess the ultimate conflict between having this ultimate, you know, self-sovereign setup where you're the only one who has access to it, is that you're the only one who has access to it. And so, you need to figure out a way that you can have a set of trusted people that you believe won't all collude against you to be able to access your funds if, for whatever reason, you become incapacitated."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "33:10",
      "start": 1990.23,
      "text": "And we actually do include this as one of the thirteen threats, is inheritance failure. we view that as a threat that you build up this wealth and then it's just easily stolen at the end of your life, that's a problem or that it's totally lost at the end of your life. There is-- there are several unfortunate circumstances. I think Matthew Mellon is probably the, the largest, I think, that's known. I think that was a, that was-- I don't think that was in Bitcoin, it was in something else, but it was something like five hundred million dollars, it was lost. so this is starting to become a real issue."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "33:44",
      "start": 2024.25,
      "text": "I But this is a, some, at some point, this is even gonna be the legal documents that you have, and the photos that you have, and the, all these other, you know, digital family heirlooms that you have, will also be passed down in a similar way. So it is, it is a really big problem. There's a lot of people doing great work here. Pamela Morgan's been doing great work here. A lot of people, and we've, we've tried to take, kind of unique tack in both having our full service and our, the Talking to those same lawyers, working with independent customer lawyers with the state attorneys. We've been doing this for, it's probably been what, six, six, eight months? Yeah."
    },
    {
      "speaker": "guest_2",
      "time": "34:22",
      "start": 2062.43,
      "text": "So, you know, this gets a lot more complicated, A, because you have jurisdictional differences, right, right, right, and B, because everybody has a different family, a different individual personal setup, and this is why we've been going a lot slower on this side where we've been trying to figure out, you know, how do we make it customizable for people while still trying to, like I said Why is those footgun paths? It get, it gets, more difficult to, to keep people within, you know, well vetted guidance when there is a wider, you know, array of possibilities and decisions that have to be made."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "34:58",
      "start": 2097.68,
      "text": "And a lot of times, your inheritors, they may not even want to keep the Bitcoin, right? And who are you to actually kind of choose for them if we're talking about individual sovereignty? Who are you to infringe on their sovereignty and their choice? you know, that would be, I think in all of our- It would be a very unfortunate case just depending on timing and, what different, different, we, you know, everybody pretty much on the team and talking about hyperbitcoinization and all this stuff, and just like, just changes in Bitcoin price, it's usually just a, you know, one or two days out of the year that have the, the widest swings, and so the timing could just be horrendous if someone's just like, \"Oh, I'm not even gonna think about this,\" and then five days later it changes, but you do still in those cases, you know, wealth and are arguably scarcer than even the twenty-one million Bitcoin. And so really trying to be very careful about those and, and thinking about the inheritors and thinking about the, you know, if they want to pass them down, if they want to keep them. the, most of them, it, it's one thing to, to educate a bitcoiner on keys and multisig, it's an entirely different thing to educate an inheritor on all of this stuff and even an estate attorney. So we've been mapping all of that out and really thinking through the kind of onboarding process from both the customer side, the direct customer side, the, inheritors side, and then also even thinking about the regulatory side and how, you can kind of minimize data, minimize trust, but also satisfy, 'cause there are a lot of requirements when inheritors kind of pass wealth and this is the different jurisdictional side. So it, I think it'll be a little while longer before we go really public with everything there, but you can expect a similar amount of detail. We started, we actually decided to push out this Casa Wealth security protocol 'cause we said, hey, level of detail that we're going through on the inheritance side, we could just address the core multisig and then these, these two documents would really fit well together."
    },
    {
      "speaker": "stephan",
      "time": "36:52",
      "start": 2211.97,
      "text": "Fantastic. and just while we're, you know, still on the topic of security as well, I, I think we, we definitely wanna also cover off the idea of being seedless. So that is something that's probably a little alien to many Bitcoiners, because the typical setup that they're thinking is, \"Oh, I've got my hardware wallet and I've got my twenty-four word seed.\" What's the difference with Casa and why this, why seedless? Sure. So"
    },
    {
      "speaker": "guest_2",
      "time": "37:19",
      "start": 2238.67,
      "text": "anyone who has set up a hardware wallet before is familiar with that, that first step where it gives you your twelve or twenty-four word backup seed phrase. And what we really decided was that When you get through that process, the, the hardware device basically says, \"Okay, you know, write this down and keep it in a safe pla-place,\" and the, there's this entire- Mountain of knowledge, you know, hidden under that simple word, you know, keep it in a safe place, is that, you know, like we've been saying basically the, the entire time now, we're trying to, raise up the bar, Higher so that the users don't have to think about all of the security considerations, of, of, you know, managing these private keys. And, and essentially, a seed phrase is all of the keys to the kingdom. So if the user has to manage the seed phrase and think about physical attacks and, and physical loss and all of that, then that just becomes another like exponential blow up in the number of decisions that the user has to make. And by just Completely throwing the seed phrase out the window and leaving it, you know, secured in hardware devices and, and, via secure enclave on, a mobile device, it just makes it a lot easier for us to reason about the security model. And since When we're thinking through the security model, we don't want to have to trust the user, and, and the various decisions that they've made, that once again, it just, it narrows down the, the, the possibilities and the footguns, really. So, it's, it is an alien thing for people who have been in the space for a while. We hope that it becomes a more common thing, but, you know, it's also an alien thing to have a fl- Flexible multisig setup that is easy to do key rotations, and that's, that's the main reason w- that we believe that seedless is okay if you pair it with a way to flexibly, replace, you know, lost"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "39:28",
      "start": 2367.84,
      "text": "seeds. And so we wrote, and with full hardware wallets, full support, I mean, that's one reason why this isn't entire system, it's not just about the software. even the incentive system around a kind of yearly fee for us as a company in providing a level of service, it's all designed around this kind of long term alignment between customer and company. And we do a lot of things that, again, we out-- we outline here in the document, but, we do maintain extra stock of hardware wallets. We don't wanna be in a case to where someone Of a store and rotate that in, and it works perfectly fine, but we also maintain stock just in case someone, they might be traveling, they might be in an international country to where they can't typically get access, and we now have global logistics expertise. We have customers in over sixty countries, and we've dealt with shipping, crazy shipping problems pretty much everywhere around the world now, and, and so we now have that access to get you a device if something fails and you need to kind of rotate something in. We've built out a, a full wallet sweep feature. You can go UTX Really fast wallet sweeps, and it's the combination of that with the hardware wallet, ease of use, with the mobile key, with every-- or, and, and everything kind of built together that makes this a manageable fast response system. but it just really shifts the model, i-- two, two kind of framings that I use thinking about this is that if you think about, you know, there's nothing, there's nothing bad inherently bad about seed phrases, that the, the reason they were designed in the first place is because you were dealing with what was effectively kind And then you had the seed phrase, but you only had one device and it was a one of one system, right? and by shifting to multisig, you end up in a situation to where you would have five total keys and five total seed phrases, and then you're protecting ten total items. And because you have this, this ability to, it's a three of five, so if you lose one key, it's okay, you can just rotate and sign with the other keys. That's a, that's something that you didn't have, that's a feature that you didn't have in"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "41:29",
      "start": 2488.64,
      "text": "But the, the, the trade-off there is that you then have to shift from being, okay, we're gonna protect everything that's here right now and just r-restore you to the exact same state, you have to shift the design of the system to being something that r-r-that responds rapidly, re-adapts rapidly. and we actually, again, we noticed that out of actually doing direct customer, interaction and, and research because we looked at when people were actually recovering single treasures or ledgers, what they would do is, so say they lost a device, they would lose the device, they would go find their seed phrase, they'd buy a, new device, they would reload the seed phrase, and they would immediately have a second device that they sent funds to. And so there's, you know, there's eight steps there to get to that second device to send funds to the second device, and then they'd wipe the old device. So they're already doing this kind of key rotation process, they're just not thinking about it. And we can simplify that down from about eight or nine steps into just three, to where it's, okay, one key's lost, okay, we're not gonna worry about that one anymore, just rotate in a new key, send funds. So it, it drops it down to three. And although it's, it is a little"
    },
    {
      "speaker": "stephan",
      "time": "42:45",
      "start": 2565.35,
      "text": "Through that, just for the listeners who might not be clear what's going on there. So, for example's sake, the person is using a three of five, and they believe that one of the keys has been, you know, tampered with or lost or whatever. So you, you would then have to say that key is now gone, and now essentially what you would be doing then is spending out of the remaining set into the new five keys set, which now has a new hardware wallet instead of that one that has been stolen or lost or tampered, et cetera. Right."
    },
    {
      "speaker": "guest_2",
      "time": "43:18",
      "start": 2598.03,
      "text": "Yeah, the, the new, three out of five set would still have four of the same, you know, public key sets as the previous, and you're just rotating out that one that has been compromised."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "43:30",
      "start": 2609.86,
      "text": "But it becomes a totally fresh set of addresses, totally new set of addresses, because even with it just that one key different, you're, you're in a totally different domain in terms of- Your address set and, and your funds, and so you're back to kind of full level of safety. And I, and I do wanna mention that we, again, we rejected, there's a bunch of features, different key schemes that we ended up rejecting, and this is actually one of the reasons why around just kind of general key sharding that we did reject some of that is that you lose a lot of flexibility around your recoverability, your ability to rotate, in a case to where you've given out a bunch of different key shards and then you decide, oh, wait a second I can give out a bunch more key shards where if you've given out, you know, four, you, you have a lawyer, you have a friend or someone else, you've given out one hardware wallet to them, you could rotate your other sets of keys and that person could still hold the same device, and they don't have to change a thing, right? And but you're in a totally new address set, you're able to move the funds, and that person doesn't have to do anything. So it's"
    },
    {
      "speaker": "guest_2",
      "time": "44:30",
      "start": 2670.48,
      "text": "just"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "44:32",
      "start": 2671.84,
      "text": "a more flexible system. Way more flexible. And you, It can be great, and we've, we've thought about some different implementations of maybe taking one key out of your multisig and doing some key sharding, but I think the key sharding as a whole, the other, the other big weakness there that a lot of people haven't really factored in is that if your key is breached before you do the key sharding, so if there's a supply chain attack or there's any of the kind of thirteen attacks we've listed, if that key is somehow discovered, you know, you may be in a case to where it's ten It was ever compromised, but that, that one time it was compromised, and then ten years down the line and doesn't matter, you know, you're owned from the beginning. Yeah, you were owned from the beginning, you didn't even know it, and you went to all this work where it's, as soon as you do multisig and as soon as you do five fresh key creations, you know, you've, it just completely eliminated that possibility."
    },
    {
      "speaker": "stephan",
      "time": "45:30",
      "start": 2730.01,
      "text": "Yeah. And so, I guess one of the things there is with, if somebody wants to do Shamir's Secret Sharing and they split it into three or five shards, let's say, now it becomes a lot more difficult for them to change after the fact. Right. Right. So that's one of the-- I guess that's one of the things you're getting at there as well. Right. So let's say I had, you know, four friends and I gave each of them a shard, but then later maybe I'm not friends with one of those guys anymore, I fall out with him,"
    },
    {
      "speaker": "stephan",
      "time": "46:00",
      "start": 2759.75,
      "text": "Go to each of those friends, give them each a new piece, whereas in a Casa model, I suppose it's like you've got different hardware wallets and you're managing it through that, and in doing so, you could even just completely disregard what-- you could, again, disregard one of those hardware keys and rotate in a new key into that set, and now you're kind of, you're good to go."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "46:19",
      "start": 2778.82,
      "text": "Yeah, you could reject an individual one key and replace just that person's key, where if you're talking about a full key-sharded set, you would-- if you were trying to do To go actually replace everybody else's too. So it just, it gives you a lot more flexibility, and we are, you know, we, we have more team-based features that are basically around. We have, we have a lot of customers that are either family offices or they're just families, and it's a spouse or, you know, two, a brother and sister or, even a small team, and we're building more kind of linkages between how people interact with those keys and how they can view the different actions that are happening, reminders, there's a ton to build out"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "47:00",
      "start": 2819.75,
      "text": "Side, and just thinking through this, this full security model."
    },
    {
      "speaker": "stephan",
      "time": "47:03",
      "start": 2823.31,
      "text": "Fantastic. Let's talk a little bit about, sovereign recovery. So I understand with Casa, there is the sovereign recovery process, which is essentially, it's an email, and you have, I think, is it the xPubs and essentially the, the redeem scripts and so on, and you would, the, the user at this point would pick up Electrum, and then they would, you know, bring their hardware wallets together and, you know, spend into their own set. Can you talk to that process"
    },
    {
      "speaker": "guest_2",
      "time": "47:30",
      "start": 2849.71,
      "text": "Right, so, you know, in order to spend out of three of five, obviously you have to have three of the sets of private keys. But the thing that I think a lot of people might not know is that you have to have all of the public, key sets. So, when you initially create a wallet, or whenever you, need this information, if you, you know, lose it, at any time, you can export it again from the Key Master app, we'll essentially give you a step-by-step guide to You use open source software along with all of the public keys, so that then all you have to do is, you know, recreate your wallet and then plug in, you know, one device at a time and, and go through a similar type of process to basically sweep all of those funds and then send it to whatever new setup you want. And, It's, it's fairly standard, actually, if you go to walletsrecovery dot org, then we have, a copy of the process on there. We're using completely standard, multi-sig redeem script, so there's nothing special required there. All you really need to know are your specific, extended public keys and then the, derivation scheme that we use."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "48:43",
      "start": 2922.54,
      "text": "And we don't, one, one note again, just kind of in the level of detail, in that email, we assume that your email could be totally pwned, compromised, and so there are only two pub keys that are actually sent in the email that has the full instruction set, and then the others you recover either directly from your devices or, within the app, but we were really trying to build even that process out, someone could attack you from that side, so we've done that very piecemeal and very carefully too, but you always have full Satoshi disappears if, if somehow there's, you know, internet access is limited in your country, you know, there, there are, tons of scenarios, and even within these extreme scenarios, you still have full control, but you also get that usability of having a full service, full software suite, full kind of people behind you when, when things are going well. Fantastic. I think"
    },
    {
      "speaker": "stephan",
      "time": "49:35",
      "start": 2974.61,
      "text": "there's probably just two key things I think, and these are, again, trade-offs that are being made for, to make it easy for the user, but I think just for the listeners just to make sure they're aware, I guess they should be aware that one, that, you know, the privacy aspect, they are doxing their coins to Casa. That's probably the main, like, probably one of the big trade-offs that they have to consider. They've gotta obviously enter into it with open eyes because they're getting the additional security of multi-signature. And I think the other one ending the your chosen rule set. And theoretically, if some, if a company, if you're with a company and that company decides to go with SegWit 2x and so on, which chain, which fork would you be on? Some of those questions as well. but I think those would be, you know, a trade-off that the user thinks about in, in order to get, okay, the additional multi-signature and the kind of guidance through the process. Would that be sort of a fair summary?"
    },
    {
      "speaker": "guest_2",
      "time": "50:29",
      "start": 3028.68,
      "text": "Sure, at the moment, and of course, people are probably familiar with the fact that we also sell the Casa node. Now, one of the things that we're doing over time is continuing to integrate all of our products and services together more and more. And, you know, it's definitely a desire we've had demand for for a while and that we've wanted to do in the long term is to offload, m, as much of the coordination and trust away from the Casa servers and actually onto the Casa node. So, you know, I think it's only gonna be a matter of time, before you're able to connect, Keymaster to your Casa node, much in the way that you can connect Satsap to your Casa node right now, though that's, you know, Satsap is going through LND, which is talking to, to Bitcoin Core, whereas on the Keymaster side, it would be more, talking directly to Bitcoin Core basically to do the, the verification of, receipts of transactions."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "51:25",
      "start": 3085.41,
      "text": "From the, from the privacy aspect, 'cause this is a really interesting point, there are, there are multiple reasons to wanna maintain privacy. definitely the biggest one is just as a pure attack vector. the second one is, you know, just keeping people out of your shit and trying to block transactions, trying to block, and that's for, for anybody that's, that's, kind of used to KYC/AML laws today, you can't even go spend if you wanna-- There are numerous cases where people just wanted to go spend ten, twenty thousand dollars on buying a Car or a house or whatever, and they could barely, you know, they could-- it took them a while to get the money out, even when they got it out, they were still getting hounded for, \"What are you using this for?\" And, you know, majority of people out there in the world are good, there are some criminals, there are even more criminals that use cash than use Bitcoin, but privacy is important for people, it's important, and, and the way we think about it, again, we've minimized the total amount of data. Once you kind of come in the door, we, we do think that there will be a world to where you will as- you'll be able to assume that e-every, you know, you go into a wealthy neighborhood, middle class neighborhood, even some poor neighborhoods, right? Doesn't matter, you're-- people are going to assume that every house in that neighborhood, regardless of socioeconomic status, has some Bitcoin. In the same way that today you would go to any house, and any attacker is gonna think, \"Oh, man, there's, you know, there's high-int TVs probably in these houses. There's, there might be jewelry, there might be, you know, family heirlooms. There, there's wealth in every one of these houses. We're gonna reach a, a state we, we think pretty soon, within five or ten years, to where that's just the case. and so it, it, I, I think that the, the conversation around privacy is going to be something more around you are going to selectively disclose parts, not everything, and that, that ability to selectively disclose certain portions, some people may feel comfortable actually using their real name and their real email address, other people want to use, you know, not use that. we don't, again, require KYC or, or, driver's license or anything else, so you do have that flexibility, but we are gonna get to a world to where people-- some people will do more or less, but that control is gonna be important, but almost everybody will have something. And so this- Idea that of just totally hiding out, and no one ever knowing that you have Bitcoin is gonna become harder and harder because everyone's just gonna have Bitcoin. It's just a question of kind of how much. So we, I, I, I described that whole process because when we were initially thinking about designing the multisig and Keymaster and the service, we, we thought through, we're like, okay, if we get five, ten years out, what's this gonna look like? And a private banking service is gonna give you all the control, you have all the data control,"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "54:14",
      "start": 3253.97,
      "text": "For certain people, it will be kind of common for some things to be there, and if you wanna have a level of service to where you do have a kind of private banking level, you get, you can pick up the phone anytime, you can get engineering support, you can get, direct, you know, question support on, you know, this, this one cousin or one brother that, you know, is terrible technically, and you want some extra recommendations on how to use, you know, you, you don't even have to say the name of the brother, but there will be certain amounts"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "54:44",
      "start": 3283.65,
      "text": "ability for that to be there while, while the customers still have control of their data or control of that in choice. but yeah, so that's the world that we're trying, that we're thinking where, where things will go. And I, and we've tried to back into how do we give them that, you know, as much flexibility as possible while still maintaining privacy, but kind of giving that, that choice there."
    },
    {
      "speaker": "stephan",
      "time": "55:03",
      "start": 3303.25,
      "text": "in terms of roadmap, I think, you know, the cold card is a crowd favorite, so, and I know, As part of the customer's set as well. Yes. Yeah,"
    },
    {
      "speaker": "guest_2",
      "time": "55:17",
      "start": 3316.75,
      "text": "definitely, you know, right now we have ledger and trezor support, and so people will have like, either one ledger and two trezers or two trezer or two ledgers and one trezer, you know, basically a mix of the different products there, but of course, it'd be even better if it was like one ledger, one trezor, one cold card."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "55:36",
      "start": 3336.43,
      "text": "And we think that it's, that again, kind of as we've planned out, we do think yeah, you know, there are gonna be some many, many smaller manufacturers, many medium-sized manufacturers. I think that we're gonna get to a world where Samsung and Sony and all these kind of name brand manufacturers are gonna have key signing devices. So we're, we're building for that and, you know, getting partially signed Bitcoin transaction support into the system, being able to fully support, cold card is a priority, we're working on that really hard and we'll be releasing news around that as soon as, as, you know, relatively soon. but that is a More integration, so between the node and between Keymaster, that will, we'll do a lot of testing there. before that, I think that we will have more news around the inheritance side, if people have questions on that or anything else, you just email membership at team dot casa, and we can touch on any kind of questions around where things are going. But there's, there's even more stuff around, so we, we do have in the document, we kind of have a list of remaining attack vectors that we are trying to, work around, and we do Even around address spoofing, that we've even one of the reasons why we use mobile keys is it's actually, it is harder to do address spoofing. We actually to rederive on, both the, the end client and on the server side, it's still possible, but it's, it's, it's definitely minimized. but there's even more work we can do in simplifying and making it easier to validate addresses across both Casa system and across, say, your sovereign recovery setup or another system just before you're even transferring funds on, and there To do, but I think that the way we think about this wealth security protocol document, as it kind of lays out, the, both the kind of, remaining attack vectors that we can continue to address and the areas for work, other features that we can add in, and then also, you know, we've got Taproot and Schnorr and, that's gonna make things easier too. So we'll be, we're working towards, supporting this."
    },
    {
      "speaker": "stephan",
      "time": "57:35",
      "start": 3455.48,
      "text": "when it comes to some of these, coming technologies as well, I think, the document mentions, some ideas around what could be done with that. I'm just trying to find that now. Oh, yeah, so that's, that's the one I was keen to ask about, just multi-signature transactions on the blockchain looking like standard transactions with Schnorr, with Schnorr signatures as well. So that's another thing right now where currently multi-signature transactions are distinguishable on the blockchain, but hopefully it sort of gets to that point where it, it, everything starts to look the same and then it's a bit more,"
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "58:12",
      "start": 3492.24,
      "text": "And you can analyze traffic even by, you know, number of keys, setup of keys. one, one thing that, even one reason why we, we mapped out this kind of rollout of three of five and then two of three and then even, single signature is that you-- we actually provide some cover in a sense by having more multi-sig transactions overall, we actually provide some cover for larger balances or larger customers. And, the more people that are using multi-sig, the more, Exposure you have from a, from a code perspective and, and, even from a support perspective of, of, i-i-i-there's a, there's a lot that comes from more usage, and so I think that just like broadening that market is actually an important point around this, this specific topic."
    },
    {
      "speaker": "stephan",
      "time": "58:57",
      "start": 3537.08,
      "text": "All right, so look, is there anything else you guys, wanted to bring up? I think we've kind of spoken to a lot of different, points. So, Yeah, if you've got anything, anything else that you wanted to bring up around, where perhaps, perhaps just where kind of Bitcoin custody is going over the next few years, what does it, what does it look like in your, in your mind?"
    },
    {
      "speaker": "guest_2",
      "time": "59:17",
      "start": 3557.24,
      "text": "Well, I mean, I think unfortunately a lot of Bitcoin custody is going to be, you know, institutionalized, custody with trusted, regulated third parties, and, you know, we, we kind of see ourselves as, you know, fighting against that tide, you know, it's going to be difficult to do. I think just a lot of the, the big money, you know, from traditional finance and investments, is going to end up going with that. Model because that's what they're used to or possibly even legally required to do. But, this is why we have focused on the individuals more though, because there isn't really anything like that in the, the traditional, financial world. We believe there's a much larger gap where, you know, custody with, with trusted third parties is a fairly well understood thing, that, you know, people have been doing that for, for hundreds, if not thousands, of years. but trying to- take a lot of those principles and make them, you know, usable by the average person who isn't eating and breathing custody day in and day out, as I think the- Really challenging thing where there's a lot of value to be gained."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "01:00:34",
      "start": 3634.79,
      "text": "Yeah. Yeah, I think that, I think that, you can think of it as, you know, historically security and privacy have really almost been like a luxury good in the sense that there have, you know, there have been titans of industry who owned their own banks and, or there have been, queens and kings who had their stash of, of, of both food and cash and gold and, you know, there, there have always been these kind of- Of having that level of, of access, privacy, wealth, you, you, it, it was a select few that had that level of control. And what we're specifically trying to do, we know there are gonna be institutions that come in, and there are gonna be institutional products, and, you know, we've laid out the, the attack vectors that even those institutional products will face, and some of those will be tested and will fail, and we do believe that a lot of individuals will shift most of their personal wealth into doing some kind of multi-sig or some kind of- Self-controlled keys because of this, on the long term, but, to get there, we have to, again, if that core problem is that privacy and security are, have historically been a luxury good and it's been problematic on, or, or just hard to do, we have to make it easier, and that's what we're set out to do is, is bring that level of wealth control, and that level of security and privacy to anyone at any cost, and that goes all the way down. I mean, we're gonna go as far as we can to bring the This, and the options around that as, as low as possible, so that we can get it to really anyone in the world, and then there will just be differing tiers based on kind of how much wealth you're storing and the security trade-offs around that."
    },
    {
      "speaker": "stephan",
      "time": "01:02:12",
      "start": 3732.03,
      "text": "Fantastic. Well, look, I think that's, gonna do it for this one. How about you guys, tell my listeners where can they find you? Obviously, I'll put the links in the show notes, but it's nice to just, speak out the links as well."
    },
    {
      "speaker": "guest_2",
      "time": "01:02:23",
      "start": 3743.2,
      "text": "I'm often on Twitter with the handle LOP, L O P P. you can also find me and a ton of educational resources about Bitcoin at LOP dot net."
    },
    {
      "speaker": "jeremy_welch_jameson_lopp",
      "time": "01:02:33",
      "start": 3753.36,
      "text": "Yep. And I'm, so I'm, Jeremy R Welch on Twitter, and then we also have at casa huddle on Twitter. and you can, you know, if you have any questions on this stuff, membership at team casa is the easiest resource. Hit us with your hardest questions. Go read the security protocol. Try to figure out any flaws you can. Hit us with all those questions. I mean, that's what it's there for, and you can just Google Casa Wealth Security Protocol and, and find that. It's a PDF, it's really easy to read, and that's what it's there for. So, dig in and let us know your questions."
    },
    {
      "speaker": "stephan",
      "time": "01:03:03",
      "start": 3783.6,
      "text": "Fantastic. Well, look, yeah, thanks for the, the work you guys are doing to help, make people, make, the Bitcoiners more, out there more secure and, more educated. So, thanks for that, and thanks for joining me I hope you got some value out of listening to the perspectives from the Casa team on some of their decisions around the trade-offs that they have made, and you can hopefully use that to inform your own decisions about what you wanna do. So make sure you share the episode with your friends so they can learn more about it as well, and also make sure you subscribe using a podcast app. One of my favorites is PocketCasts, which used to be a paid app and it's now free for both Android and iOS, so make sure you look that one up. I've got a bunch of cool interviews coming up. With Brian Bishop, Pamela Morgan, Christopher Allen, Drew Banzel from Unchained Capital, and more. So remember, the show notes and the transcript for the episodes are on my website, stephanlivera dot com. That's it from me, guys. Thanks for listening, and I will see you in the citadels."
    }
  ]
}
