{
  "episodeId": "SLP152",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "nvk": {
      "name": "NVK",
      "role": "guest",
      "tag": "NVK"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:08",
      "start": 7.95,
      "text": "Hi, you're listening to the Stephan Livera podcast, a show about Bitcoin and Austrian economics. Today for episode one hundred and fifty-two my guest is NvK and we're talking about CK Bunker and Bitcoin backups. This show is brought to you by Kraken, one of the world's leading Bitcoin exchanges offering a high quality platform with high trading volume and low fees, no minimum or hidden fees. Kraken have Twenty four seven support. They offer Kraken Pro mobile app delivering all the security and features you love about the Kraken exchange in a beautiful mobile first design for Bitcoin trading. Some recent updates on the app have added the ability for you to add markets and list favorites, and you can also receive vibrating feedback on major actions. Kraken also offer an OTC desk for those seeking more private, personalized service for large block trades. There's Kraken Margin up to five times and Kraken Futures up to fifty times leverage. Go to Kraken dot co. Or find Kraken Pro in the App Store or on Google Play. Check out Unchained Capital, a Bitcoin native financial services company. They're offering a really cool two of three keys multi-signature vault product. You can use Trezor or Ledger, and Coldcard is coming soon. It's really easy to use web interface, and you still maintain control, and you can hold two keys geographically separated. If you need to access USD liquidity but without selling your Bitcoin, Unchained offer collateralized loans. So you can put up some Bitcoin, that Bitcoin is stored on chain in dedicated multisig addresses, it's never rehypothecated, and you can share in the security of your Bitcoin by holding one of three keys. I'm really impressed with Unchained, they offer excellent services, I've done some recent interviews with Parker Lewis and Will Cole and Drew Bonsall, go and check those out, I think you'll enjoy learning more at unchained-dashcapital.com. So you've got a Bitcoin seed, but have you backed it up? Go to ciphersafe.io, they're producing So if you've invested in a Bitcoin hardware wallet, you've got a 12 or 24 word BIP39 seed, but is it backed up in a way that's fireproof, waterproof, rustproof, petproof, and tamper evident? The CipherWheel comes in a wheel shape, it masks the words of your seed, and you get some little tweezers and tiles, and you put in four tiles for each word, and that's how you back it up. So make sure that you or your loved ones have access to your bitcoins if an accident occurs. Orders are going out"
    },
    {
      "speaker": "stephan",
      "time": "02:30",
      "start": 150.0,
      "text": "Here's the interview with Rodolfo. Rodolfo, welcome back to the show."
    },
    {
      "speaker": "nvk",
      "time": "02:34",
      "start": 153.54,
      "text": "Hey, man, thanks for having me. Again."
    },
    {
      "speaker": "stephan",
      "time": "02:36",
      "start": 155.82,
      "text": "Yeah, this is your, I think your third appearance. So, you're, you're definitely getting up there in the league tables. I think Vijay and Pierre are leading at four times each. So, we'll see, we'll see. I'm a"
    },
    {
      "speaker": "nvk",
      "time": "02:45",
      "start": 165.31,
      "text": "pretty competitive guy, man. We're gonna have to record a second round after this."
    },
    {
      "speaker": "stephan",
      "time": "02:52",
      "start": 171.85,
      "text": "Hah"
    },
    {
      "speaker": "stephan",
      "time": "03:00",
      "start": 180.18,
      "text": "The CK Bunker product and a couple other things to talk about as well. But look, let's just start with the bunker. So can you tell us what is CK Bunker?"
    },
    {
      "speaker": "nvk",
      "time": "03:12",
      "start": 191.84,
      "text": "Yeah, so, so CK Bunker isn't really a product. It's, it's actually like a- Really free open source project, right? That like people can just sort of fork it and do whatever they want with it. y-y'know, I'm sure other hardware wallets are gonna end up forking and, and just making it work for them as well. I-it's more like along the lines of a BTC Pay Server kind of deal. it's just, we, you know, we've been waiting for somebody to make it and nobody did it, so we're like, hey, you know, fuck it, we'll just make it ourselves, right? so, so anyway, so CK Bunker is a roll-your-own Bitcoin, right? I, I mean, so you have a easier UI and, and the server, right? To have a automated code card. So, so let's say, for example, you, you wanna use multisig, right? A-and, and you want to have another entity, right, co-sign your transactions, right? Because you, you don't trust yourself or you don't trust your position or whatever. So CK Bunker essentially allows you to have a secondary cold card, right? Connected to a computer somewhere, ideally a safe place, running. Completely automatically, with some policies, right? Say like, you know,"
    },
    {
      "speaker": "nvk",
      "time": "04:44",
      "start": 284.3,
      "text": "velocity, right? So you can only spend one BTC per day. a-and, and you only co-sign transactions for you in that matter. So, just running through like an easy example there. So, you have this thing running, you access it via Tor. Or on, in, in, in person kind of thing, but let's say it's remote. So you access it via Tor, you have an onion address, it does all that stuff for you. You go to this page, you log in, and then you start your transaction on either on your cold card or Electrum or whatever. You-- and then you just upload your PSBT file for this to cosign, and then it can even broadcast the transaction for you."
    },
    {
      "speaker": "stephan",
      "time": "05:25",
      "start": 325.15,
      "text": "Excellent. So let's talk through, who are the people who might use that? So I think off the top of my Businesses might have a use for this kind of product, an individual who wants to use it as part of his multisig setup might think about using this as part of his product. Who are some of the typical users for this product that you can think of, or this software that you might think of?"
    },
    {
      "speaker": "nvk",
      "time": "05:50",
      "start": 350.19,
      "text": "So I, I think that the initial sort of, the, the, the low-hanging fruit people, right? definitely small businesses. like France has already integrated this stuff in CipherNote so that they can use it for- Or, Bitcoin bull, it took them a couple days, they're already like almost there. so like most small businesses have this need where they, they need a, a separate machine to either co-sign or just run their, their sort of their hot wallets, right? a-and, and you can automate exactly, so, so, you know, you have your time of the day, you have your quantity, all that stuff. you- We can add users to it so that each user also has a policy, so your, you can empower your employees to do stuff, but you don't have to trust them fully, kind of thing. and then you can have, another thing I see, I guess one of the reasons why we made this is that I got a lot of requests from people that been wanting to be the, Sort of like the, the co-sign service for family and friends, right? So, y-you know, they're the only one out of, say, their fifty people circle, right? the, the social circle, who, who have the technical chops to do anything really, Bitcoin, right? but they don't wanna hold the bags for friends and family either. I-it's not a nice place to be in, especially, you know, if something happens to you, right? You don't wanna be that kind of responsibility. So what this does is it really empowers you To sort of like be that cosign bank, right? That cosign service for your friends, a-a-and then you, you show them how to do their part, right? A-a-and then you just essentially run this cosigning for them. another thing this provides is privacy, right? Because you're only really, doxing your xPub keys with your, with yourself, really, right? So if you're running this for yourself, you're not sharing your addresses with anybody else or any other"
    },
    {
      "speaker": "stephan",
      "time": "07:52",
      "start": 471.92,
      "text": "service. Okay, so we could think of it like the more privacy-focused Bitcoin businesses might have a use for this kind of service or server or this CK bunker, as you say. so As I understand, you can set up like a multisig. So for example, you might have two partners in a Bitcoin business, and they want a third key, and then they could set up CK Bunker as their third key, and they could maybe set it up so we need some kind of special spending policy where, let's say, one of the partners plus the CK Bunker can sign the transaction. Is that one way to think of it? That's"
    },
    {
      "speaker": "nvk",
      "time": "08:28",
      "start": 507.53,
      "text": "exactly it, right? So for example, let's say me and you, we're running a, a small, say, Bitcoin brokerage And let's say we're not even in US, right? So we don't even really use Bigo because you don't want to deal with a US company, right? in that case. So let's say that me and you, being partners, we can move the total balance of the wallet, right? Anytime. But, you know, being proper business people we are, we wanna make sure our partners cannot either be coerced by themselves. be a risk of being coerced by themselves or have to trust in each other to that level either, just to keep things simple, right? So what we do is we can each do transactions up to a certain amount per day or per week or whatever it is your, your time and amount. We doubt each other, right? So we would use the bunker to cosign. But let's say we decided that we wanna move all the money to a new wallet or whatever, the two of us could cosign and ignore the bunker to get it out. So that would be a two out of three."
    },
    {
      "speaker": "stephan",
      "time": "09:33",
      "start": 572.71,
      "text": "Gotcha. And so it could be useful in scenarios where, let's say, one of the partners is away on a holiday or something like that, and then you still need them to cosign to make, to pay some business expenses, but you could have set up in advance the CK bunker, for So one of the partners can spend in line with the spending policies set up in advance with the bunker, such that they can, you know, pay the suppliers and do those kind of day-to-day things, so long as they're not spending the full balance, let's say. I mean, this is just a hypothetical where just- No, that's"
    },
    {
      "speaker": "nvk",
      "time": "10:03",
      "start": 603.44,
      "text": "exactly it. You, you totally got it. that, that's the idea, right? It's, it's really to sort of, you, you create this, this thing is like a, a roboc signer, right? It, it All the flexibility you need with as much or as little trust you wanna give it, right? So that's very helpful, right? A-a-another big thing is, y-y-you know, just having, geographical separation, right? So you can have a box that can co-sign in a different city or different country. that's super powerful because, y-y-you know, you're not beholden to local sort of coercion or, or local issues. Or, or let's say you have, you know, an earthquake or whatever, right? And you have to leave and you lose the wallet, and, you know, you can have somebody else co-sign with that box in a different place. Y-y-you know, having geographical separation, i-it's not just for sort of like, like actual security, security, right? It could just be redundancy too. You can even have two co-signed boxes. So you can have two bunkers co-signing each other in different places too."
    },
    {
      "speaker": "stephan",
      "time": "11:10",
      "start": 669.63,
      "text": "Right, I see. Yeah. So you could have like one in your country and one in like some other totally different country and like- Yeah, with different"
    },
    {
      "speaker": "nvk",
      "time": "11:15",
      "start": 675.47,
      "text": "users. you know, we support different levels of what we call remote hands, right? So we have different trust levels for the box itself. So you can have a local user. That doesn't necessarily have the PIN for the machine or anything, but he has a special PIN to cosign only, right? But he doesn't have access to the actual private key of the device."
    },
    {
      "speaker": "stephan",
      "time": "11:38",
      "start": 697.75,
      "text": "sorry, let's, let's, let's take a step back and just talk about the setup then, so just to understand, so for the users who are thinking, okay, I wanna use this bunker thing, how do I do it? Let's say I wanna do a two of three, and in that, let's say that's a, that's that example, right? Like you and"
    },
    {
      "speaker": "stephan",
      "time": "11:57",
      "start": 716.94,
      "text": "setup. How do we do the two of three multisig setup in that scenario?"
    },
    {
      "speaker": "nvk",
      "time": "12:02",
      "start": 721.71,
      "text": "So you install Bunker, right, on, on, on your computer. right now it's a Python package, but it, it has a UI and everything. It's, it's fairly straightforward. I'm pretty sure within no time, this stuff is gonna be a one-button install on, say, BTC-Pay or, or MyNode or FullyNode, that kind of stuff. I believe it's a, it might already be one-button install on CipherNode. So, so let's say you have the thing there, right? It's installed. So what you do is you plug in the, a cold card that, that, is gonna be the master for that, instance, and then you plug in the other ones, and you sort of create the multisig. Like setup, right? You create a multisig wallet between them."
    },
    {
      "speaker": "stephan",
      "time": "12:45",
      "start": 765.48,
      "text": "Gotcha. So for clarity, we would have three cold cards in that setup. you would have one, I would have one, and then the bunker has one, right? And then we would jointly together have a two of three multisig. Exactly."
    },
    {
      "speaker": "nvk",
      "time": "12:58",
      "start": 777.58,
      "text": "it doesn't have to be a cold card, by the way. for the bunker itself, it needs to be a cold card for now until somebody else builds for other hardware wallets. But, the co-signing parties don't have to be-- they just have to sort of, be, capable of doing the same type of multisig wallet."
    },
    {
      "speaker": "stephan",
      "time": "13:16",
      "start": 795.91,
      "text": "Gotcha. And they would have to have PSBT, basically?"
    },
    {
      "speaker": "nvk",
      "time": "13:19",
      "start": 798.8,
      "text": "Yeah, I mean, they have to have PSBT, but they don't even have to be a hardware wallet. It could be Electrum."
    },
    {
      "speaker": "stephan",
      "time": "13:25",
      "start": 804.72,
      "text": "I"
    },
    {
      "speaker": "nvk",
      "time": "13:25",
      "start": 804.82,
      "text": "see, I see. Yeah, it's, it's pretty, it's, it's very, very flexible. That, that was the whole point of this."
    },
    {
      "speaker": "stephan",
      "time": "13:31",
      "start": 810.97,
      "text": "Right. So as an example, you could have a Coldcard wallet, and I might have an Electrum wallet, and- Then the bunker obviously has a cold card, because that, that's what it is. And we can jointly sign that, and I might have, say, an offline Electrum computer or something like that, and I bring a PSBT, file to that laptop to do the signing, and then I would bring it back online to do the broadcast aspect, something like that."
    },
    {
      "speaker": "nvk",
      "time": "13:56",
      "start": 836.38,
      "text": "you don't even need to do that, like, so you can go through this onion address that it creates. a-and then you just upload the file there, the, the PSBT file. And that's it. It's, it's all sort of like web-based, but it can be offline web or online web kind of thing, but it's like a web UI."
    },
    {
      "speaker": "stephan",
      "time": "14:15",
      "start": 855.19,
      "text": "Right, I see. And this comes back to the, it would host a Tor service, right? And so for the listeners who aren't familiar, can you just give them just a very basic background on how they would use that? I mean, you would fire up Tor Browser, and the CK Bunker would give you a Tor Address, and you just basically paste that address, you go there, and it's basically just a website on Tor. Yeah,"
    },
    {
      "speaker": "nvk",
      "time": "14:36",
      "start": 875.88,
      "text": "that's it, that's all. Because see, the, the beauty of Tor for this, more than the privacy stuff, is that it gives you, SSL tunnel between your browser and remote and the device. It's fairly secure, right? A-a-and it's like a, a closed tunnel there. So the, the, you, you, your last concern about man in the middle and all that stuff, right? It, it, you really get a and, and the, and what's really cool is that the private key for that, that Tor server is stored in the cold card too. So there's a lot of good stuff. Well, it, not really, it's kind of encrypted and then the encryption keys and the code, I'm not gonna get into the implementation of it. But the cool thing is that there is an extra level of security there for the Tor server."
    },
    {
      "speaker": "stephan",
      "time": "15:27",
      "start": 926.9,
      "text": "So that is the Tor online setup, and then what if we wanted to do a local setup? So let's say, we've got a friend, and we set up the bunker at his place, like he's got a garage or something, and we can keep-- he's a trusted friend between you and me, and then we wanted to do like a local setup, how would that work?"
    },
    {
      "speaker": "nvk",
      "time": "15:47",
      "start": 947.29,
      "text": "It's the same. You get a, you get a computer, you set up a bunker on it, and, and you can just use it offline. You just have to bring the files there and you In the UI of it and use cosign for you."
    },
    {
      "speaker": "stephan",
      "time": "15:59",
      "start": 959.26,
      "text": "In terms of, what you have to install, so I was just looking through some of the docs, I saw is it a c k c c protocol, which is the same thing that you install if you wanna get your, if you're on Linux and you wanna use Coldcard with your Electrum, that's the same thing you install, And so that's ma- that's basically the main thing that you would have to install. That's"
    },
    {
      "speaker": "nvk",
      "time": "16:19",
      "start": 978.97,
      "text": "it? You just do, you just install, you install CKCC, you install, Bunker, and Bunker is gonna have all its dependencies, right? there's a few. and, you know, we run the whole show for you there. I-, it's, it's all sort of fairly plug-and-play. with a little bit of command line right now, right? Because you gotta get it there. It's, but you know, as soon as nobody makes it, yeah, exactly, right? I mean, somebody's gonna have a one-button for this, you know, in a, in a week or two."
    },
    {
      "speaker": "stephan",
      "time": "16:47",
      "start": 1007.17,
      "text": "Yeah, I do think it's an interesting idea. Let's talk now through the setup of it and, you know, if you wanna set up spending rules, users, derivation paths. So let's talk through, spending rules first. Like, how, what are some example spending"
    },
    {
      "speaker": "nvk",
      "time": "17:06",
      "start": 1025.82,
      "text": "Essentially, you, you create users, right? And these users are actually stored inside the policy file, inside the cold card, okay? And then each user, you're, you're gonna have to, you're gonna choose how this user authenticates. I, is it, i-is it like a, a user that's just the cold card itself, right? So like no people, no human input? is it human input? And if it is human input, is it, Google Authenticator or is it a password? we give you full flexibility there. So what's really cool is you can have remote hands. So, so let's say you don't wanna fully trust a cold card to just cosign one BTC per day automatically, right? You still want a human to go and, and look at the transaction on the screen Right? This user, you can force this user to use Google Authenticator for one time, pin, sorry, one time password, or you can just have a standard password for them. It's also numeric, and they'll just type in on the screen. Now what's nice is, we give you full review of all the transactions on screen so you can sort of, you know, review everything before you sign. and then we also give you sort of like different levels of security on the device. there's security considerations of course, because CoCard is, is open source, right? And, and, and, we use-- we only use a secure element to store the seed, when it's essentially off, right? When, when, when it's unlocked, the seed is in memory of the MCU, the essentially the, the less secure part of the device, so that we can do everything in open source. the problem with that is, you know, there are sort of like very extreme possible sort of side-channel attacks and things like that. Like that. So, you know, this is, this is a hundred dollar solution for a fifty thousand dollar problem, right? So, you know, if you wanna get a proper HSM, right, that, that, that's like has all the proper sort of physical, properties that you need and, and all the automation and all the certification and all that stuff, we're talking about a fifty to a hundred thousand dollar machine, right? now, you know, if your physical considerations aren't, you know, some- Body with side-channel attacks capabilities coming to your, to your facility, right? You can solve that problem with a hundred dollar device, which is, you know, quite nice for a business, right?"
    },
    {
      "speaker": "stephan",
      "time": "19:36",
      "start": 1176.34,
      "text": "Yeah. And I think the other thing is, one important, perhaps, neglected factor with Bitcoin and things like that is the first factor is if somebody even knows you have Bitcoin, right? Like that's probably the first part. So if they don't even know you're using this kind of setup, well, that's already a big factor."
    },
    {
      "speaker": "nvk",
      "time": "19:53",
      "start": 1192.67,
      "text": "Exactly. And, and you, and you can, and you can Worked it out, right? I mean, you can have, one is that the cold card doesn't have to be, plugged to the computer at all times, right? I mean, you can unplug it during certain hours of the day or whatever. you can also have a power isolator, and you can put this inside a locked metal box that's EMI shielded, and that's it. So essentially, think about it like a, a, a properly altered, say- Small little gun case, right? That's, that's gun, safe that you put in a drawer. You can have that stuff wired in and sitting in there, and then you have the employee or the person that needs to put a pin to go in to change. Or if it's fully automated and you don't need a human input, then, then you can even sort of make that even more secured in something, even with a battery, maybe, right? So even if you have a power down or something."
    },
    {
      "speaker": "stephan",
      "time": "20:47",
      "start": 1247.22,
      "text": "Okay, so I guess if we're talking about attack cost, right? Mentioned before as well around how much would an attacker have to spend to try and break it, and, you know, we shouldn't think of things in binary like it's unhackable or attackable, it's, it's more just like how much should someone spend or how much, you know, technical expertise is required. And I think you've mentioned for the cold card kind of rough figures as well there. If, if you were to think of that in terms of like Would you think of it like, you know, don't secure more than X number of bitcoins or X number of money on, on a bunker-style device? Or is, is there any kind of guidelines that you can share for the listeners? I don't"
    },
    {
      "speaker": "nvk",
      "time": "21:29",
      "start": 1288.63,
      "text": "think there is a lot of guidelines because remember, right? If you're doing multi-sig, I, I mean, you know, let's say, let's say it costs fifty to a hundred thousand dollars, maybe more, to, to attack the, the cold card bunker location plus time, right? plus know-how and all-- this is like, it, it, it, it's quite like, quite an advanced attack. This isn't like your average run-of-the-mill stuff, right? But let's say somebody has the capability of getting to that, right? They still don't have the other leg of the multisig, which is you. So, y-y-you know, this is, this is quite robust in terms of single point of failure. So even if they get to it, it's not a big deal. Now, let's say you're using this to run a hot wallet and it's single signer, right? Then now maybe you, you wanna sort of consider what's your, what's your threat level there and how much you wanna keep in it. because you, you could, this can run as a single signer as well."
    },
    {
      "speaker": "stephan",
      "time": "22:30",
      "start": 1349.72,
      "text": "I see. So in that scenario, let's say it's a single signer scenario, then would you say don't keep more than fifty thousand dollars on it, or what, what would you sort of-"
    },
    {
      "speaker": "nvk",
      "time": "22:39",
      "start": 1358.56,
      "text": "I, it, it, it, you know, like, let's say you live in a very safe country and you're, and you're very comfortable with your physical security, right? I mean, then, then it's not a big deal, right? Because They, you, you know, if somebody's gonna cut steel doors and, you, you know, get through all through that and, and, and then shoot some security guard and then know how to do side channel attacks and, you, you know what I mean? It's like this stuff starts becoming like very Mission Impossible, right? exactly, right? So, so a, a-as long as you have the, the layers and you think this stuff through, it will become very obvious to you what is your threat, like, what's your, your risk management in terms of amount of money you"
    },
    {
      "speaker": "stephan",
      "time": "23:21",
      "start": 1401.44,
      "text": "Yeah, no, that's fair, that's fair. And I think in practice, most people who would want to use this would be doing multi-signature on it anyway, so they might be doing two of three or three of five or something similar based on how many people are in that Bitcoin business, and so as you mentioned, you set up the users and they have-- they could either be using Google Authenticator or, some other kind of TOTP, you know, like the one-time password style thing or just a- Set password style thing, and then we've got derivation paths. So from watching the video, I think there is a way to lock it into certain specific derivation paths. So can you tell us about that and why would somebody use that?"
    },
    {
      "speaker": "nvk",
      "time": "24:06",
      "start": 1445.69,
      "text": "So, it, it's nice to, for example, you could whitelist a single derivation path, which is really cool, right? So you can only send to a certain derivation path of a certain xPub. You, you can only, Sign a certain derivation path as well, so you can, say, lock out, other parts, other accounts of the same, private key, the same seed, right? to me that's very powerful to be able to sort of like set that out, on the policies."
    },
    {
      "speaker": "stephan",
      "time": "24:36",
      "start": 1476.01,
      "text": "So just, we might just clarify, just for listeners who aren't familiar with that, check out episode ninety-nine with Andrew Chow. but I guess the high-level way to think of that is you've got your seed, and then off of that you can generate, you know, And then from that xPub you can generate all these different addresses in different accounts, and maybe the quick way to think of it is like the derivation path is sort of like a folder structure, a folder location for a specific- setup that you have, and I guess you can think of it like this way of locking into a certain der-derivation path is to say only spend into this specific account structure. Would that be a fair summary you would say? Yeah,"
    },
    {
      "speaker": "nvk",
      "time": "25:16",
      "start": 1516.09,
      "text": "yeah. I, I mean, the idea is you're, you're just saying, you know, you can only spend from this account, not from this other account of that same seed."
    },
    {
      "speaker": "stephan",
      "time": "25:23",
      "start": 1523.41,
      "text": "in terms of o-other policy, so can you tell us a little bit about that? I think I saw there were some other ideas there, like PSBT warning"
    },
    {
      "speaker": "nvk",
      "time": "25:33",
      "start": 1533.04,
      "text": "Let me just open my docs here, I'm, I'm starting to forget all the options that we have for the, for the policies. So you can choose to have, like a confirmation message, right? So, and then we can check for absence of stuff too, right? So in the absence of, say, the log not being, like, not having a micro SD for the log, don't sign, right? we- Can check for, you know, like, e- so for example, if you wanna, if you wanna sign a PSBT that's non-standard, right, to our heuristics, so we check, say, for, we do some sanity checking on outputs, right? So in case somebody's trying to do something in the middle in the PSBT or something. We can do it so that if there is a warning, it doesn't sign, period. Or if there is a warning that you have to okay the warning, you choose. Right? So, so you can really sort of break this down to your level of, of need there. And then, you know, and then you have sort of, you have the whitelists, you have the, the time, you have the max amount, you have the users, you have the minimum amount of users. So for example, you can have a single cold card in an office, right? And say you are the boss, right? So you aren't in the office, you wanna cosign a transaction, but you don't wanna trust a single employee. So you can have"
    },
    {
      "speaker": "stephan",
      "time": "27:06",
      "start": 1625.52,
      "text": "I see. So it's kind of like a way of getting multisig without doing multisig, if you will. Yeah. Or on top of multisig. I see. and let's talk through that process then. So if you try to sign but you haven't met the policy requirements, what happens then? Does it show you the error? Does it say, \"We require X, Y, and Z\"? No, so you-"
    },
    {
      "speaker": "nvk",
      "time": "27:26",
      "start": 1645.81,
      "text": "So this is the cool thing, right? Like, w-we gave you the option of, of having privacy or not having privacy of policy. So, In case we show you the policy file in the UI of Bunker, so you can see the policies there, in the other option it just fails."
    },
    {
      "speaker": "stephan",
      "time": "27:43",
      "start": 1662.68,
      "text": "I see, because you don't want to reveal exactly the spending condition. What's your"
    },
    {
      "speaker": "nvk",
      "time": "27:46",
      "start": 1665.94,
      "text": "maximum? Exactly, right? so, so, so we give you the two options, and then we have sort of like the, the more nuclear option, 'cause we like nuclear options. Where you can lock the policy file on that cold card forever. So essentially, it can never be used again as an, as a normal cold card or re- or anything. It's just, once it's set, it's set forever, a-and that's it."
    },
    {
      "speaker": "stephan",
      "time": "28:14",
      "start": 1693.82,
      "text": "So we're using the cold card Mark three as a normal wallet, and then we can turn it into an HSM, right? Like this bunker idea. can you tell us a little bit about how you switch between-- what are the main differences that we should think of when it's in HSM? Mode or bunker mode. You"
    },
    {
      "speaker": "nvk",
      "time": "28:29",
      "start": 1708.53,
      "text": "become quite obvious. It's like you essentially go into the HSM menu and once it's set up and connected to the bunker, the, the card is connected to the bunker, it goes into HSM mode. It has that, the night rider like little bar going side to side on the bottom of the screen, and it, it's got like, this essentially like dashboard right on the tiny little screen showing you You know, how many transactions went through and, and, like the time period and, what else do we show there? We, yeah, so we show essentially how many approved, how many refused, and the time period left. and we have a little thing for the PIN."
    },
    {
      "speaker": "stephan",
      "time": "29:12",
      "start": 1751.94,
      "text": "Yep. And for clarity for the listeners, this is, Mark III only feature, correct? Like you can't use Mark I or Mark II with it."
    },
    {
      "speaker": "nvk",
      "time": "29:20",
      "start": 1759.7,
      "text": "Yeah. Yeah. So we, we actually tried to make it work on the previous models because we wanted people to be able to use their old models as this stuff, right? reduce some e-waste. But the, the problem is there's simply just not enough memory, right? Like there's a bunch of stuff we need to run there and, and there's just no room. y-you know, we're talking about, we count bytes, like we literally go through menus to remove spaces to, to fit more code in. That's, that's the kind of sort of memory management we have to do there."
    },
    {
      "speaker": "stephan",
      "time": "29:54",
      "start": 1793.77,
      "text": "Let's talk a little bit about this idea of the storage locker. So just from looking through documentation, I saw this idea that it's like another way of storing some random data, sensitive data into the secure element on that cold card, or in now, in now it's a bunker cold card. Can you tell us a little bit about that and what, what might people use that for?"
    },
    {
      "speaker": "nvk",
      "time": "30:18",
      "start": 1818.26,
      "text": "So when you have a sort of like a remote server or something like that, oftentimes you have to- Store a few things like, say, your, Tor private keys, right? They're not necessarily Bitcoin related or cold card related, right? But they, they have to be stored somewhere. You can also store your server SSH keys, you can store whatever you need to store for that server to run. And then we give you a way to have a policy in which, say, for example, you only give The, the bunker, access to those, to that sensitive data once at boot, or more times, like you choose your, like how often you need to see that data. But what's nice about that is, if there is physical sort of attempt at that computer, right? Some of the sensitive data is no longer available to that computer. Because oftentimes you just need to see that stuff once a boot to set up something, and then that goes into your memory and then you're done. You can hide it."
    },
    {
      "speaker": "stephan",
      "time": "31:20",
      "start": 1880.13,
      "text": "I see, yeah. So this is like a security architecture point to talk about there. Okay, no, I understand that. and there was also this question on the documentation around, a possibility of not using the master xPub but using a derived path instead. So can you first just explain for the listeners who might not be familiar what's the difference? There between the master xPub and the derived path."
    },
    {
      "speaker": "nvk",
      "time": "31:44",
      "start": 1904.17,
      "text": "So it's essentially like, it's like an infinite tree there. You can have, you can have your, your xPub, right? Your heart, like your first xPub, out of derivation path there. But you can also derive another xPub out of that xPub. So you can have like a secondary sort of derivation path there, and that really just helps sort of like segregate things and, and, and give you like a whole other sort of set of rules you can have instead of, again, segregation of funds without having too many seeds, for example. Some people, the people that have the need for that will become very obvious for most people, it's, it's a little bit sort of out there in terms of feature. And one of the main reasons why we wanted to keep this thing so sort of- Like loose in terms of features and, and very sort of flexible, it's because, you know, as people try to do, like, like Lightning, network, HSMs, or they, they, they're trying to do eventually confidential transaction stuff, or they're trying to do, mixing services, or just joint markets or whatever, right? some of that stuff isn't baked into Coldcard yet. but people are thinking of clever ways. I just saw on Twitter today some kid managed to use a cold card as their lightning channel private key holder, which is Pretty awesome."
    },
    {
      "speaker": "stephan",
      "time": "33:17",
      "start": 1996.55,
      "text": "Yeah, I believe C-Lightning has that function now where you can open the channel from a hardware wallet and then close back into the hardware wallet. So what's"
    },
    {
      "speaker": "nvk",
      "time": "33:25",
      "start": 2005.12,
      "text": "nice is, you know, as you make some glue, you can have a automated, you know, like Hardware wallet doing your lightning channel stuff, right? So that's pretty powerful. Like one of the biggest issues with, with lightning is having a hot computer with a private key in it, right? So if you can just sort of take that out of the computer,"
    },
    {
      "speaker": "stephan",
      "time": "33:49",
      "start": 2029.0,
      "text": "it's a huge gain already. And I think you were experimenting and researching into this direction as well as poten-- of potentially having a cold card and potentially using Bunker as your lightning hardware wallet. And yes, it's not It's not gonna be fully cold cold, but it'll be more like a warm wallet, and that's a bit more secure than just having the keys straight hot on the computer. So can you tell us a little bit about that?"
    },
    {
      "speaker": "nvk",
      "time": "34:12",
      "start": 2051.77,
      "text": "Yeah, that, that's exactly it. I, it's, well, it really comes down to that idea of security in depth, right? Like, it's like if we can add some more layers, like any layer counts, right? Because it's one less, one more thing an attacker has to figure out, the attacker has to get over it, right? So"
    },
    {
      "speaker": "nvk",
      "time": "34:33",
      "start": 2072.87,
      "text": "Having hot keys on computers is very, like, it, it makes me feel uncomfortable. So, so, so I hope that, you know, eventually somebody who knows and understands Lightning way better than I do, can sort of like make some of that glue work."
    },
    {
      "speaker": "stephan",
      "time": "34:49",
      "start": 2089.14,
      "text": "Yeah. And now one other comment, and you mentioned this as well around the flexibility of CK Bunker, but I'll tell you one thing that I'm seeing, even from me when I was trying to research this, I was almost like, there's too many options. And I had to try to make, think up examples to try and make it real for the listener, because sometimes when people are given almost too much choice, they don't know what is this actually good for, what is it actually usable for. And again, this is early stuff, I appreciate that, but it might, maybe one direction that this can develop is to have a few kind of stock standard setups, right? So this two of three example that we were talking through, that might be an easy common stock standard setup that people might use CK bunker for. Do you have any other ideas around what Like a typical use, a typical stock standard setup."
    },
    {
      "speaker": "nvk",
      "time": "35:37",
      "start": 2136.61,
      "text": "Well, you know us, right? Like we're terrible at making like stuff that's like noob friendly. So, one thing was really cool, Peter, my co-founder, like he went on a rampage on Twitter and sort of giving examples, and we added those to the homepage of the bunker project, so you can see those there. So, so yeah, so I, I guess some ideas, a-and these could be automated, right? Or they could be wizard. By, either users or us or, the, the stuff will get easy. It's already easy, it's just that you have to sort of read the manual, right? hopefully soon you don't have to read the manual, you just press buttons and the stuff is done for you. But, so yeah, so the, the examples from the actual homepage right now are, so geographic separation, you have, you know, cold card on the other side, then you cosigns for you. another one is, is, is to, to have your, your warm wallet, you know, doing some spending for you to a whitelist, say this is your in-between, removing funds from an exchange. and you need sort of like an in-between you and your very cold to go to your operational wallet. businesses understand operational wallets, you do need one, right? You take, you, you, you earn the BTC, and then you need to figure out how much I need for bills, how much I need for that, and then how much is gonna go to cold storage, right? So this is very good for that. you know, you can have one that's like, say, the meet me in the bunker TM. so, you know, so- So it's like a three out of five, and maybe two of them don't actually have cold cards, they just have, auth, Google Auth, authenticators to cosign i- this super useful to have people that don't actually have, to Bitcoin sign, they're just password signing kind of thing? because it's like less wallets you have to set up and stuff, so it's very good for managers kind of thing. you can, you can have, a, a very good way to do message signing this is just easy for people to do it in general now 'cause there's a web for, a web UI for it, you know, and then you have your storage locker, maybe that's, again, it's your like server keys or your database keys or something like that. and then you have your classic sort of, you know, I am the person who cosigns for the whole family. So, you know, you create different derivation paths for each part, for each person, and that's how you do it. maybe you have multiple instances of Bunker running for each person as well. I'm sure somebody will come up with a nice little Raspberry Pi solution for that eventually, you know?"
    },
    {
      "speaker": "stephan",
      "time": "38:31",
      "start": 2310.74,
      "text": "That could be a business model for them as well. They could say, \"Hey, I'll set up Bunker for you, \"and then you and Have your own little bunker thing going. Yeah."
    },
    {
      "speaker": "nvk",
      "time": "38:38",
      "start": 2318.0,
      "text": "And you don't even have to trust them, which is really cool, right? I mean, the worst that can happen is they, they have one of the keys out of the multisig, so they can't really rob you. So, so that's sort of where it's at now. I think once there's some videos, there's some people using it, it's gonna become a lot more obvious. Just we didn't wanna pigeonhole this into a single solution sort of thing because This is already for advanced people anyways, like not, not super advanced, but this is for people who can sort of run their own BTC Pay kinda deal. So might as well give people the flexibility and, and wait for them to sort of start pigeonholing some solutions out of this."
    },
    {
      "speaker": "stephan",
      "time": "39:20",
      "start": 2359.92,
      "text": "Yeah, for sure, for sure. Yeah, I think that makes a lot of sense to me. Yeah, so look, let's, let's change it up a little bit. Let's talk more, now more about the cold card. So, you recently were, you, you were just telling me that you made the cold card documentation public as well, and you've got the GitHub page going for that. What was the, thinking there?"
    },
    {
      "speaker": "nvk",
      "time": "39:39",
      "start": 2379.38,
      "text": "So, you know, we have like good technical documentation, but I, I think our documentation can definitely be improved More, more noob friendly sort of language or examples or thing like that. So, we decided to sort of move all the documentation for all, like for our current projects, into a single repo and make it public, a-and so that, you know, people can help. It's, it's like, if you don't like the documentation, well, then make a pull request and, and help us improve it, kind of thing. so if, if people wanna help, we'll be, we'll be very grateful. it's, it's, github dot com slash coinkite slash coinkite dash docs. But th-there's links everywhere, and it's on our Telegram as well."
    },
    {
      "speaker": "stephan",
      "time": "40:30",
      "start": 2429.6,
      "text": "People have different ways that they're doing support channels as well, right? So some Bitcoin projects, they're big on Telegram, so it's kind of, go to the Telegram and ask the questions there, and other people are just like firing off questions on Twitter or on Bitcoin Reddit and elsewhere. So there's all these different places, and then some people are just not even in that world at all, Going to the website, you know, Coldcardwallet dot com or Coincard dot com and expecting, you know, okay, everything should just be there, right? So that's"
    },
    {
      "speaker": "nvk",
      "time": "40:55",
      "start": 2454.56,
      "text": "right. And, and I think like people also ask questions differently, they use like different language, so like just sometimes just having the same answer or the same question just asked differently helps a lot. You, you know, it's like the way you ask your question is kinda there somewhere, helps? and we hope to add search at some point soon as well to the docs, and then that should sort of like really make it a lot easier. We, we also needed to document Bunker, which had a quite a bit of docs. so that was also motivation to finally, you know, move all this stuff into some place that other people can contribute."
    },
    {
      "speaker": "stephan",
      "time": "41:30",
      "start": 2489.63,
      "text": "Yeah. And I think if anyone is a, the sort of person who is often helping answer questions, then if they're starting to answer the same question many times, then it starts to make sense for them to do a pull request, put the question and the answer, and put that into the documentation there, and then whenever they get the question, they can just link them to that exact point where they've already answered the question. It's"
    },
    {
      "speaker": "nvk",
      "time": "41:53",
      "start": 2512.88,
      "text": "Very efficient."
    },
    {
      "speaker": "stephan",
      "time": "41:54",
      "start": 2513.84,
      "text": "Yeah, so that's something people can look at, and so, also wanted to talk about secure elements, right? So there is a big, again, lot of back and forward. I don't wanna get too like toxic or whatever, but I think it might just be useful to talk about, you know, just the facts, right? What are the ways of thinking about keeping your keys secure in Bitcoin, and, some people, are more adamant, let's say, about the use of secure elements, and then you've got- But other people who are more, let's say, they're, you know, and trying to be neutral, trying to be, you know, fair to their point of view, they might think of it more like, \"Hey, everything needs to be open source, otherwise, I don't know if I can trust what's inside that secure element.\" What's your thought on that?"
    },
    {
      "speaker": "nvk",
      "time": "42:39",
      "start": 2558.95,
      "text": "So, so that's sort of like a false premise. I, it's unfortunately hardware is, is like, is a very deep, very deep technical sort of pigeon, like, like a, like rabbit hole. But I, I mean, there really is no-- aside from a few sort of projects that aren't really out there yet, and I don't know if they'll ever ship, there, there really is no really fully open source hardware, right? unless you have your own electron microscope at home. And you can check the die of the microchips you're using, you are trusting somebody, right? So, so then the question is, how can you minimize that trust as much as possible, right? And there are ways, right? I mean, there is our approach, there's the, the Trezor approach, there's the Ledger approach, right? so, but secure elements, what, what are-- So secure elements are essentially like a, a purposely made- Microchip to keep secrets secure, right? That's it, that's, that's its purpose, right? And then there is many flavors of that Many ways to go about it, many ways to do it. and then you have general purpose micros, right? They're essentially like Swiss cheeses, right? Like they just have holes everywhere, they weren't meant to do security, they're just, you know, they're just doing their job. Running a toaster, running a microwave, running a hardware wallet, right? It's the same microchips that are in your microwave, they're in your hardware wallet, kind of thing. Okay. What's cool about simple MCUs, right, the, the simpler, microchips that Trezor and Coldcard use, that are open, is that they have a lot less complexity, so less attack surface, right? But they're still completely full of holes. So what, what we do Coldcard is we have a very dumb secure element. The secure element that we use, it's actually fixed function. So essentially, you can't really, like, run code on it, right? What the-- what this secure element provides to us is like essentially a storage locker. And, and then it has, of course, a few sort of like crypto calculators in there, we call them crypto accelerators, but let's call them crypto calculators in there that can do crypto for you, They don't do the Bitcoin curve, so we're not doing any Bitcoin stuff with those closed source calculators. Right? We're only using the secure storage locker of that chip, which is very good. Right? Is it infallible? No, there is ways of attacking it, it costs hundreds of thousands of dollars, essentially. could you maybe create an attack that-- anyways, point is, it's very expensive to attack, right? and then what we do is, we actually keep your seed encrypted with the open source code In the secure element. So the secure element doesn't actually have visibility to your seed either. So if somebody, if they say if there is like a, a backdoor by the manufacturer of that secure element, right? They still can't see your seed, they would have to get the other part, from the MCU to be able to decrypt that, and we use one time pad, which is the only non-cipher that's essentially unbreakable, To break that, they'd have to attack the other chip as well. So in our case, you essentially have to attack two chips and you have to have, an efficiency like, A success rate of a hundred percent for both, or you can't marry them together and get that key extracted and also decrypted. So it's a very, very, very, very advanced attack, right? A-and that was our solution to find the right sort of compromise, the right set, set of trade-offs so that we can have a fully open-source device, all the code is verifiable, and because it's a very dumb secure element, no code of ours in there, you can actually buy that secure element from DigiKey, say, right? You could desolder it, take the one that we provide you with, put a new one in, reload the firmware, and- And prove to yourself that we don't have any shenanigans running because, you know, we didn't provide you that chip, right? in the case of Trezor, they have no secure element, there's, there's essentially zero physical security, right? That, the device, I don't know if they designed it this way, but now the, the literature on it, the, the, the marketing on it really, says, you know, there is no physical security, this is essentially a, a layer against computer- Mauve, use your twenty-fifth word, right? We advise everybody to use the twenty-fifth word, right? Everybody should use, passphrase, regardless, if it's for real HODL, but, you know, there is, again, multiple levels of needs. So you don't wanna have a twenty-fifth word for your operational wallet, but you also may want this, this to be secured against an evil maid attack or against, you know, some basic physical security. that's what we personally wanted to achieve, right? It's, it's like just raise the cost of attack to a certain degree, and, and we think Mark 3 is there in, in a very sort of good spot and then there's Ledger. Ledger has a true and tested approach to this, you know, it's, it's a very known approach in the pin and chip sort of like, security industry. it's a very fair approach, but There is no choice, it has to be closed source because they're using, a bunch of the, the libraries of those chips probably. I, I don't have full visibility to it, but I assume that's because they're using a lot of the libraries, the vendor libraries, And probably part of their certification, who knows, right? But essentially the base layer of their solution, their apps could be all sort of like open source, but the base layer of their solution, the, the actual sort of, let's call it the chip OS, right? Because they're running everything inside the secure element, is fully closed source. So, and, you know, I mean, I, I don't know if they have pool with the, with the vendors to maybe change that one day, or maybe- Maybe it's, you know, maybe i-it's just a, listen, it's a lot easier to do security products being closed source. That's the honesty about it. It's like, I'd love- If I could get away with being closed source, it's just I wouldn't trust it myself, so I didn't do it. But it's a lot nicer because you, all the script kiddies, all the lower level researchers, they're not gonna be able to find a lot of your problems because the source is not there, you cannot just go read the bugs."
    },
    {
      "speaker": "stephan",
      "time": "49:48",
      "start": 2987.56,
      "text": "And, it, it is a bit of a challenging thing because as I recall, Ledger came out with their Donjon Ledger blog post talking about the unfixable seed extraction attack available on the Trezor One that was a little while ago, and then more recently, Kraken Security Labs, disclosure, my podcast is sponsored by Kraken, but Kraken Security Labs came out with basically some of the more details around how to actually do the seed extraction attack against both the Trezor One and the Trezor Model T. And, this kind of does come into that."
    },
    {
      "speaker": "nvk",
      "time": "50:20",
      "start": 3020.22,
      "text": "Yeah, I was a little bit annoyed about that post because I, you know, to me it felt like just reusing the, the knowledge of somebody else. Like, I gotta give it to the guys from Ledger. I mean, at least those guys are doing all this stuff from scratch. I have had many back and forths with them. they are trying to attack our stuff too. You know, they were successful with some stuff, not with everything. They're trying to work on the Mark III now, still waiting to see if they That suppliers get, like, i-if somebody's putting that kind of effort and money into it, y-you know, at least, y-you know, there is a, a level of wasted time for very obscure, expensive attacks, but at least we get something out of it, right? Like, you have like professional people trying to attack stuff. I guess like- Part of what annoys me is sort of like the, the PR cycles out of the stuff, the-- because it, it's fudging like the, the, the, this industry, right? Like it's making everybody like sort of make stupid decisions, right? So people hear about some attack and they immediately sort of try to move their hodl somewhere else and they might screw themselves, right? So I, I, I think it's important, but I, I think the whole sort of trying to, to snipe the competitor with attacks is sort of getting old."
    },
    {
      "speaker": "nvk",
      "time": "51:44",
      "start": 3103.86,
      "text": "And, you know, like there is diminishing returns there. I think that I, I, I really welcome, especially very advanced stuff that costs a lot of money that, you know, like you might not necessarily even be able to afford, as, as a, as, as a vendor. we're talking about like, you know, like million-dollar equipment plus time plus know-how people. Like, it's like, it's, it's serious This stuff, right? on top a-and this is just to do research on hardware, this isn't people actually making anything, right? so There is, there is a lot to be gained by the industry for that,"
    },
    {
      "speaker": "nvk",
      "time": "52:30",
      "start": 3149.66,
      "text": "but what I really sort of got tired of it is like, you know Lower level research done with research of somebody else for blog posts and PR, I think that's sort of like detrimental to the industry, just creates more paranoia and it's not helpful."
    },
    {
      "speaker": "stephan",
      "time": "52:49",
      "start": 3168.94,
      "text": "Right, and I, I can appreciate that, you know, one of the important things that we're always talking about with Bitcoin, not your keys, not your coins, and I wouldn't want to have users be scared out of self-custody, right? And so I wouldn't want them to think, \"Oh, I'd rather leave it on the exchange,\" because I think that's way worse, right? I would rather, you know, I think they should, take those steps and Though we're kind of living in this world where it can be confusing for a, for a person who's like a newcomer to the industry, they might think, \"Oh no, I thought that thing got hacked, or I saw some blog post, or I, I heard a news article or whatever.\" so it, it, as long as the message is that you should try to, you know, progressively take steps towards bettering your self-custody."
    },
    {
      "speaker": "nvk",
      "time": "53:31",
      "start": 3210.56,
      "text": "Yeah, like, I mean, you, you have to do your own research. There's no way around that. If you wanna be your There really is no alternative to that. I think that, again, like, you know, even for me, right? I, I was in this space, I had other products, other services going on, and, and I did my own research, and I wasn't happy with the available options, so, you know, we made our own solution, and we ended up making that into a product, but, You know, I can only give my personal sort of, set of preferences, with my own sort of biases, but my own set of preferences. You know, it's like To me, if you don't have a secure element, like, y-y-you know, like i-it's, it's a problem, it really is. And, because, you know, you're not getting some very basic sort of set of, of defenses. listen, any hardware wallet is gonna be better than a computer infected with viruses, that is true. but I think that's a very low bar to expect from a hardware wallet. I, I think that you have to be able to survive a certain level of attacks before spilling out the beans, right? yeah, yeah. And then, you know, being closed source is, is something that I just- Personally can't, can't live with, for my hodo. especially for seed generation. seed generation, you, you shouldn't trust Even the, the trust, the, the trusted, the true random number generator on a secure element, I-- it's like that's one of the reasons why we put the dice feature there. it's because, you know what? If you're gonna hold real money, or if your money is gonna become real money, because number go up. y-y-you know, it's, you, you have to invest, right? I mean, it's like kinda having like a ten dollar bike lock for your three thousand dollar bicycle, right? I mean, why would you do that? So- You, you know, all these harder wallets are very cheap for the kind of money that people holding them. So, do you know, like, it's, it's like, people like to make fun that we keep on, you know, making you harder, but like, I'm not gonna stop, right? It's like- The security bar is gonna keep on getting higher and we're gonna keep on making new hardware, right? Like, and, and that's it, that's my personal view of how this thing needs to be done, right? Until I have something that sort of meets that bar of that period in time, I'm not happy, I'm gonna keep on making a new one. it's your choice to buy it from us and, and sort of, you know, have the stuff that we make, that we'll have a new version in, you know, a year or two kind of thing If you don't want that, well, then get something else that's been around forever and has the holes that you expect to have. I, it's, what's nice is there's options."
    },
    {
      "speaker": "stephan",
      "time": "56:29",
      "start": 3389.35,
      "text": "Yeah. I think we have to recognize that this is a cat and mouse game and it's constantly shifting. And so, i-it's just difficult to expect that a product from four or five years ago or whatever will stand that test of time, rather than you having to continually up your game, and everyone has to just continually up their game. You know, before Bitcoin"
    },
    {
      "speaker": "nvk",
      "time": "56:49",
      "start": 3409.28,
      "text": "I mean, even the security industry never had to hold like actual secrets of this level at consumer devices, right? Like, not, not like this, nothing like this, in open source. You, you, you know, I was talking to like a manufacturer that actually makes this stuff for the last, you know, a hundred, you know, fifty years, that puts chips in cars and all kinds of stuff and tries to keep things secure, they just, they just never had to deal with an industry like this. They're not used to like people spending half a million dollars trying to break their chips. Just To break their chips. It's, it's a whole other sort of, it's, it's a whole new world, right? And, and Bitcoin's very new, all this stuff is new, the Bitcoin curve isn't supported by a lot of stuff. So I don't think we're gonna get away with just sort of like not making changes to the hardware. I, I think that's just sort of, you know, it's just not possible. if you don't care about that, then get a laptop, drill out the, the radios and the microphones and all that Use that, just remember to destroy the memory once you're done with it, with a drill or a gun, because you just never know what kind of information the machine could have leaked to itself, and, you know, it's just the reality of it. There's, there's just no-- It's much easier to do that with a hardware wallet because it's so simple, the attack surface on a computer is ludicrous."
    },
    {
      "speaker": "stephan",
      "time": "58:18",
      "start": 3497.94,
      "text": "I think the other thing with that is also looking at things like multi-signature as well, right? Like, but again, there's complexity with So the user has to trade off with that. And, oh, look, in fairness, there is also complexity associated with changing hardware wallets every year or two, right? Because you've got, you might screw something up with changing over and things like that. Nah, we made that easy. We made that"
    },
    {
      "speaker": "nvk",
      "time": "58:37",
      "start": 3517.07,
      "text": "easy. You just, you just do the Microstee backup and you move it to the next one, and then you just import it in. It's-- that was, it used to be a pet peeve of mine, right? Because I used to have to move hardware wallets, and it's so, so now you do the micro SD thing and it's done, it really is done. But yes, I, I, I take your point, right? Like, none of this stuff is simple, and, and, and everything is in flux until this industry has, you know, thirty years on its belt. We're ten years in, it's much better now."
    },
    {
      "speaker": "stephan",
      "time": "59:09",
      "start": 3548.56,
      "text": "Yeah, yeah. and this is a theme that I've seen you speak about before as well, which is a lot of people screw themselves out of their own coins, right? And so it's important to talk Backups and how you secure them, and also this topic of segregating your coins. so do you wanna just open up on some thoughts on ways to segregate your coins? Like some examples I can think of, KYC coins versus non-KYC coins that you, you might have a separate stash for that. And then you also wanna think about it from a day-to-day spending, right? So let's say you've got, you know, whatever a hundred dollars worth on your phone, but that shouldn't be the same as, you know, how, like, a warm Having a cold wallet, and then you got to think about, well, do you want to do multi-sig on that cold wallet as well? So can you tell us a little bit about how to segregate Bitcoin? Yeah, so"
    },
    {
      "speaker": "nvk",
      "time": "01:00:01",
      "start": 3601.05,
      "text": "I, I think it's, you, you can't just have one single device and that's where all the stuff is, and that, you know, is just sort of the end of it all. Y-you really have to think it through because again, number go up. So there's a lot of people who had, y-y-you know, like, say, fifty coins in their phone back in the day, and then they forgot that they had fifty coins in their phone back in the day, and that was ten dollars. Right? So, so then the time passes, right? And then, you know, now you have fifty, five hundred thousand dollars. Right? So now you can't even cross an airport thing anymore without sort of possibly getting arrested for the end of your life, right? So I, I, it is, again, in constant flux, right? Price, security, and everything else. So, y-y-you know, it's the same way you check your investments, right? You go in your investment account and you look at your stuff, or you do your accounting once a year to do your taxes, right? Why don't you do a security review, right, once a year? Look at your stuff. Y-you know, again, people screw themselves out of their coins more than they get screwed out of their coins. So, the chances of an advanced attack against you are much Ruining up your coins. So make sure you have backups for all your wallets, right? Make sure these backups are appropriately segregated, distributed in different geographical locations, they're encrypted if they have to be encrypted, they're unencrypted if they don't have to be encrypted. And if you have encryption on backups, do you have a backup of the backup? Do you have a backup of the decryption key of the backup? Right? Make a little tree. Get a piece of paper, make a little tree. Three of like, y-y-you know, a flowchart of like, here's my wallet, here's my seed, here's my backups of the seed, here's the encrypted backup of the seed, here's, you know, my encryption key of the seed. Do I have backups for that? So just draw it out, right? And then you're gonna have there also your phone wallet, your, say, if you're a business, you might have your BTC Pay wallet, your cold wallet, your trading accounts, right? So, so just chart it out, in paper off of a computer, please, because you might have a hacker watching your computer, and then you just describe all the stuff you have, right? Obscurity on your backup setup is very important. Right? and, and then, you know, and then you wanna look at your, your tree of, of, of Bitcoin security backup, right? And see, okay, these are single points of failure, right? If I get coerced, if I don't get coerced. So, you know, should I split this into two? But if you, see, when you do multisig and you have two wallets, now you have to think about two backups too. Really, four backups, because it's two backups for each, maybe, right? It, it's very important to draw this stuff out. Have a full picture, see where you stand, see if you're comfortable, make sure that if your house catches on fire, all the stuff on the tree doesn't catch the fire with the house. because as much as it's nice to have a metal thing, you, you just never know if the thing is gonna melt with the house, right? You could have failure, right? So, do you have enough site backups? Right? Maybe it's in a different jurisdiction, maybe it's a different country, right? So, and it's encrypted in there, right? i-it's very important to think this stuff through. I could give you a bunch of examples, but Odds are, they aren't gonna be right for you. I really, really would like to encourage people to just draw this stuff out, do research, set it up. You don't have to do all the things initially, right? You just slowly improve your setup. and then you do your once a year audit right after the taxes, or you know, positive the taxes. a-a-and, and make, make it a thing, make it my yearly security review. A-and, and also what's nice about that is you might start finding coins that you forgot you had in some places, right? I mean, it's like pocket change, right? and but because number went up and it's been five years or whatever, right? Or ten years, you never know, you might find some very interesting, Pots of gold in, in your setup. So let's not forget those coins to begin with, right? Like make sure you have, y-y-you know, very, good, note-taking of which exchanges you have accounts in, how much coin you have there. The passwords for that stuff, and, and you have backups of that stuff, you know, because say an exchange goes down, let's say there is a lawsuit, they might need you to provide some proof of how much you had or It, it, it's just, you just never know tomorrow, right? So, so just, you know, make sure you have notes of everything and you have a very good picture of your security, setup. Your, i-it's just that's the kind of preparation that really, if anything, helps you sleep at night."
    },
    {
      "speaker": "stephan",
      "time": "01:05:16",
      "start": 3916.1,
      "text": "Yeah, yeah, yeah, for sure."
    },
    {
      "speaker": "nvk",
      "time": "01:05:17",
      "start": 3917.56,
      "text": "It's, it's a big one, right? And then you can also think about now the next step, which is super hard still, which is inheritance, right? You have to figure out if I get hit by the bus, which is the ultimate attack, right? I think it was Vijay who said that. The You know, do you have the means to pass on access information of recovery, right? Continuation of life, sorry, continuation of business for businesses or, you know, pass on wealth to your family and children? It's, do you have all this stuff available to them, all the exact information? You, you know, the derivation paths of everything. So there's a lot to it. Listen, being your own bank It's never-- it'll be definitely easier than it is now, but it'll never be as easy as just deferring all that stuff to somebody else and taking an IOU, right? So, so, so definitely do your own research and, and try to figure out all the scenarios slowly, like you don't have to freak out, but, but go through it."
    },
    {
      "speaker": "stephan",
      "time": "01:06:20",
      "start": 3980.05,
      "text": "So let's talk through just a basic example. Let's say somebody is, they've left their coins on an exchange, and now they're like, \"Okay, I've just heard, you know, Rodolfo say, 'Hey, I should, I should take my keys off the exchange, and I need to keep that backed up.'\" So, for example, you know, they could get a cold card"
    },
    {
      "speaker": "stephan",
      "time": "01:06:40",
      "start": 4000.16,
      "text": "Phrase, whatever, four or five words, passphrase, and they would want to have, steel, like CryptoSteel or Billfold or Cyphersafe, kind of product. Disclosure, Cyphersafe is a sponsor of my podcast. but you could be using one of these steel products and have maybe one for the cold card seed and potentially one for your passphrase. Yeah. And you could keep them in different locations, obviously, right? Yeah. So"
    },
    {
      "speaker": "nvk",
      "time": "01:07:06",
      "start": 4026.84,
      "text": "a, another thing I, I highly recommend is, in this one- The reasons why we made this thing is like, use the Micro SD backup, okay? I, it isn't fireproof, it isn't, y-y-you know, nuclear proof, but, it's, we, we have these industrial grade cards, they're fairly good, y-y-you know, you still have to, still have clear text backups, right, on your steel plates in different locations and all that stuff, but Those steel plates should be very hard to get to, right? So say you have hardware failure, right? You want the means to restore your, your operational stuff or your backups like much easier without sort of really,"
    },
    {
      "speaker": "nvk",
      "time": "01:07:54",
      "start": 4074.99,
      "text": "dealing with clear text backups, right? So, you know, make two, three, four micro SD backups that are encrypted, right? And then The nice thing about that is the, the micro SD's could be offsite somewhere, right? But they're encrypted. So, you know, it's not ideal if somebody gets hold of them because eventually one day they could try to break it. I mean, the encryption on them is quite decent, so it would take quite some time and you'd know by then, and then you'd have moved the funds. But You have these non-clear text backups somewhere more accessible, right? Say safe deposit box, right? You don't wanna leave clear backups in safe deposit box because if a banker gets in there, they can see it, right? So you, you have these encrypted backups there or for your multisig or whatever, right? Doesn't have to be single points of failure, and then you can have the passwords for that, for the decryption of those microSDs, very available."
    },
    {
      "speaker": "nvk",
      "time": "01:08:57",
      "start": 4137.18,
      "text": "Like in your password manager, it doesn't really matter because the cool thing about those is that those don't have money, right? So you can't do anything with those. But, in, in, in, you know, you, you break your hardware wallet or, you know, you lose it or something happens, right? You have the means of very fast, very, safely restoring, access to your funds without dealing with your more complicated, You know, wealth transfer plates in the moon, to somebody else, right? You, you can deal with all this stuff a lot more reasonably and safely, without touching computers, without doing any of this stuff. I, I, I find that a, a very overlooked, issue around this stuff, just being able to operate again, And, and this is one of the most common case scenarios. It's like somebody breaks their wallet, somebody lose their wallet, they need to quickly, if they lost the wallet, y-you know, simply transfer to a new one. That means, you know, they have to be able to, to transfer the stuff, they have to have access to it without going to two different countries to get their plates."
    },
    {
      "speaker": "stephan",
      "time": "01:10:10",
      "start": 4210.67,
      "text": "Right. So I guess quickly then, just to summarize that, it would be something like, okay, I-- my card went up in a fire or I lost it or- Or someone compromised it, then in my password manager, I've got the encrypted backup password, and I've got the micro SD backup in the safety deposit box somewhere. I'll go pick that up, and I would use my passphrase from the, sorry, the password to the encrypted backup to kind of unlock those funds. And then you might need to have a couple hardware wallets just on hand, just so you have something new to put it into as well. So that's something people kind of want, need to think about from a practicality standpoint."
    },
    {
      "speaker": "nvk",
      "time": "01:10:46",
      "start": 4246.77,
      "text": "Exactly. Like have redundancy, right? Like have- You know, depending on how much money you have, right? Or, or like how much funds you have, or how many segregated wallets you have, like have multiples of it, right? Like make sure they're properly safe. So for example, one good thing that I highly recommend to people is have a initiated hardware wallet Like an extra backup of one kept with the seed. So if you ever need, because your one broke, right? Or you wanna pass on to family, instead of having them have to figure out how to load that seed, the correct derivation path, and all that stuff, you already have a hardware wallet ready to go there, with the PIN written right on the screen, right? Because it's with the seed anyways. So i-it's just nice to have redundancy and ready to go, you can't emphasize that too little. So, so that's one of the parts. And then, for example, if you have multisig, especially for multisig, wallets are complex, right? The, the derivation paths, the scripts, whatever it is that, however you set up your multisig, make sure that you have proper backups that are ready to go for each of the legs, right? Each of the signers. you know, again, maybe set up a second wallet at the same day that you're doing the setup, that you have your, your Faraday cage, tent, and your hat, and your underwear, you, you know, you're already all set up, right? So just do it twice, or three times, and have that stuff properly set up, and just make sure you don't have those things laying around, right? Like make sure that the, the backup redundancy is properly stored securely and all that stuff. But, that's, that's very helpful."
    },
    {
      "speaker": "stephan",
      "time": "01:12:30",
      "start": 4350.91,
      "text": "And one Be a good reminder for people as well, is that, if you're feeling uncomfortable by some of these things, when you first set up your cold card or whatever, whichever hardware wallet or whatever setup, test doing the recovery then, right? So you might spend five dollars into that wallet just to have a small amount there. That's right. And then practice deleting and recovering into your backup, just to kind of prove to yourself, yeah, my backup works."
    },
    {
      "speaker": "nvk",
      "time": "01:12:55",
      "start": 4375.95,
      "text": "No, that's, that's, yeah, I, I mean, I forget that always when I'm giving people advice, but that's Just go through the process of essentially screwing yourself, right? Make sure you delete, you go into the menu, destroy the seed, now you have a, a cold carded dollar seed, and then try putting the seed in back again and make sure everything works and you see those funds again on whatever Thing you're gonna use, like Electrum, whatever you're gonna use. If you see the funds again, you can spend them. I mean, you know, you know you can recover from backup, right? That's essentially testing backup recoverability, which is, which is very important."
    },
    {
      "speaker": "stephan",
      "time": "01:13:32",
      "start": 4412.78,
      "text": "Yeah. So that's a good tip for users who are, because I can understand some people who just leave their stuff on the exchange and, well, I mean, they, they might think, \"Oh, I'm too scared about using a hardware wallet.\" And this is one way to prove to You need to prove to yourself using this kind of idea of, you know, set it up and spend, you know, five dollars or just a small amount there just to prove it to yourself."
    },
    {
      "speaker": "nvk",
      "time": "01:13:57",
      "start": 4437.53,
      "text": "I mean, it's like pretty much all businesses fail eventually, right? So, I mean, y-y-you know, even if it's not nefariously, right? Like, I mean, exchanges go out of business, right? And, and, and then funds can get into ongoing legal battles, right? It's just, it's just part of, it's the cost of doing business. So,"
    },
    {
      "speaker": "nvk",
      "time": "01:14:19",
      "start": 4459.95,
      "text": "A service to, to, to, you know, use Casa, use Unchained, you know, like, get the funds out of single points of failure they're just giving you an IOU. but if you're trading, I mean, listen, you have to have the funds hot, that's just how it works. Just, just figure out your, your risk assessment, a-and, and threshold that you're willing to go."
    },
    {
      "speaker": "stephan",
      "time": "01:14:41",
      "start": 4481.2,
      "text": "Yeah, and obviously minimize the amount you leave on the exchange, right? So people should be periodically flushing it out into their own holding rather A couple other broader things, just with the open dimes. One question and discussion I've seen is around, you know, what's the failure rate on open dimes, and how careful should people be with, you know, people putting money onto an open dime and using that for peer-to-peer trading or whatever."
    },
    {
      "speaker": "nvk",
      "time": "01:15:07",
      "start": 4507.24,
      "text": "So I, I hate the idea of, again, telling people how much they should risk their money kind of thing. So OpenDime doesn't have a backup, okay? It was not designed for that. It's designed for you to do trades of, risk appropriate amounts, whichever that is for you. It's think in terms of like cash in hand and, y-y-you know, you have to figure out that yourself. So Coldcard, sorry, OpenDime was designed to fail forward. Okay? So, in, in most cases, if it's gonna fail, it's gonna fail Before it allows you to deposit any funds, right? So essentially, if it gets destroyed in, in shipping or, you know, it happens, right? I mean, we ship like tens of tons of stuff to in all kinds of countries, right? So, y-y-you know, if you see how customs handle packages, so y-y-you know, you will have devices that fail and we do replace those, but so- When you put it in the computer, it, it's, it's gonna check itself, right? And, and, and, and, and the way it's sort of built is that, you know, if there is minor failures in it, it's just gonna fail And it's not gonna give you a deposit address, which is nice, right? It just means you have a dud, but at least there's no funds lost. there is the case, right? I mean, this is still a manufactured device. the numbers right now are about one in ten thousand, that we'll have, like a failure post deposit. it's pretty small number. a-and Of those, we managed to recover a hundred percent of them. So these are people who sent us the device either because they-- I mean, if you see the things that people have done with these devices. I mean, Jesus Christ. No, I mean, like, you know, you have like people who carry them in keychains with like amounts of money that you, you would not believe. I do not wanna dox people or whatever, but We're talking about like, like real wealth amounts, right? A-and carried on keychain and the thing is dangling, it wasn't designed for that, and it's like, you know, destroyed kind of thing. You know, people flew over, we took the device over, we took it to our lab, and we managed to get the funds out, right? There is ways of taking this to even more expensive labs, depending on the amount, that might be worth it. And anyways, point is, chances of them failing and not being recoverable, are, are pretty tiny, but still there, there is no backup. So they weren't designed for holdout, they were designed for commerce, they were designed for privacy. So if you wanna have your, your mixing bucket party, where everybody brings a open dime of, or, or a few open dimes with, with the same amount of money in it, and everybody sort of mixes in a bucket, and then have a physical mixing party, great. If you wanna use it to buy a car, if you wanna use it to, to buy stuff, that you wanna be able to just, y-you know, you don't have to wait for"
    },
    {
      "speaker": "nvk",
      "time": "01:18:18",
      "start": 4698.92,
      "text": "For that, it's not for you to hold the long term. If you wanna hold the long term, either use Coldcard or at least initialize the, the OpenDime and backup the private key. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "01:18:29",
      "start": 4709.86,
      "text": "Also, you had some comments around, stablecoins recently, so, stablecoins something to be- Are they something that people should fear or are they something that people should just accept that they're just gonna happen anyway and they might actually help people get into Bitcoin eventually?"
    },
    {
      "speaker": "nvk",
      "time": "01:18:48",
      "start": 4728.34,
      "text": "I, I mean Bitcoin is still in the, in the very early stages, right? of, of the stock to flow, if you wanna look at that way, or of the adoption curve, if you wanna, whichever, whichever orthodoxy you subscribe to, it's too early. So Bitcoin is gonna be extremely volatile, right? And, and it's very hard for you to do basic everyday business operations with an extremely volatile currency, right? It, it, it, that's the reality of it. So, people are gonna have to hold, especially businesses, they're gonna have to hold some, some stable coin. That might be the US dollar, right? That's why we have bank accounts and some of that stuff. very toxic stuff. so my, my, my belief in that is, I, I never could really sort of get into the stablecoin stuff because of the Ethereum underlining technology that's like garbage, you know, barely works and all that stuff. I don't really-- I mean, people understand my love for Ethereum already. ha ha ha. So, I think, Liquid, and I think there is a few other ones going on right now, technologies, what they do is they essentially allow us to have some of that stuff, they're still sort of federated, but at least they're using Bitcoin security. Right? So they're, they're pegging some of that stuff back to a Satoshi on the chain or whatever it is, the source of truth is Bitcoin. so, so that gives me a lot more Piece isn't the best way of looking at it, because, you know, all stablecoins will have to have a, counterparty, so there is always counterparty risk. But at least now the, it's not at least on, on JavaScript, right? It's, we're not gonna have, you know, a stupid sort of, you know, bug that causes everybody to lose their money and then you have to roll back the chain. So I think what we're gonna end up having in the future, or at least the near future, is, you're gonna have your gold, right? Which is your Bitcoin, and you're gonna have your USD, which is gonna be a, a stablecoin. and what's cool about stablecoins is, you, you know, you could, you could use Bitcoin futures as some of the counterparty to stabilize the actual underlying, the, the, the, the asset, which is gonna be that stablecoin, you can have You, you know, USD deposits, you can have all kinds of stuff, and you can have mix and baskets of that stuff, right? So you can de-risk it by having a lot of different stuff underlining it. And, and I think we can't really get away with that. Like one of the biggest features of the US dollar, right, is its stability. For-- we can argue to death on, on what stability is, where the US dollar is going, the shit show that it is, and all that stuff, right? But To the average person, you know, looking at the bank account, you at one dollar is pretty much that one dollar with, y-you know, say minus ten percent of, of purchase power per year, right? Like if you wanna be sort of whatever, right? Like some average thinking about that. But at least like, that's, you know, Bitcoin moves ten percent in five minutes, right? It's, it's, so it's a completely different universe. So, I really think, and, and this is one of the reasons, a-aside from, you know, having a central point of failure, I think one of the main reasons why the US government went after Libra is that Libra was going to be US dollar based on a bunch of currencies that competes on the stability feature. Right? Bitcoin doesn't compete in the stability feature, at least not for now. So, I think all the stable coins in different jurisdictions are gonna cause so much grief to governments, because it's gonna be impossible for them to curtail all of them, right? And then you can have all kinds of jurisdiction arbitrage with them, and you can have other coins on top of other coins. It's, it's such a cat-and-mouse game for governments. It's gonna keep them very busy. And, and while all these people are busy with all the stable coins, you know, Bitcoin wins. so, so I, I really like this idea. A-a-and another very cool thing is even though they have this counterparty risk, they're not as secure. You can still self-bank the stable coins, right? So you're gonna be able to have your hardware wallet having, you know, you have your Bitcoin and then you have, say, your, your confidential transaction-based coin, right, like Liquid. So, That's aside from all the privacy features you could have in this stablecoin, so, so we don't have to sort of make too many compromises on Bitcoin to gain a lot of stuff, by having sidechains. That's why I always liked the idea of sidechains. It's just, you know, for them to do-- to be done right, it took a long time, Liquid still has a lot of downsides, but I think it's the least worst of the solutions, this far. so that's sort of like my thinking on stablecoins."
    },
    {
      "speaker": "stephan",
      "time": "01:23:59",
      "start": 5039.32,
      "text": "With stablecoins, it can also be that the US government might not necessarily crack down so hard on Bitcoin, because people might just use the stablecoins, and in some limited sense, for a limited amount of time, it might help the US dollar's dominance, right? In the short to medium term, because more people will- Dollarize instead of, you know, going to other currencies because they'll just go to the US dollar stablecoins. And so in some sense, they might not wanna- You know, the eye of Sauron might not be trained on Bitcoin for a little while longer, because it can sort of stay under the radar for a little bit longer."
    },
    {
      "speaker": "nvk",
      "time": "01:24:36",
      "start": 5076.94,
      "text": "It's similar to Tor. Think about it this way, right? The US government created Tor They, they want Tor to, to remain Tor because they need Tor too. So, y-y-you know, like, i-it's very hard for you to kill something you may need that helps you too, right? So, i-it's tricky. As long as it doesn't take too much Of your, of your pie, you, you might willing to tolerate it, and you might just not be able to kill it either, right? Because you, you can have a US dollar that's based on euros."
    },
    {
      "speaker": "stephan",
      "time": "01:25:07",
      "start": 5107.42,
      "text": "Right. Yeah. And, the other thing that strikes m-- that comes to me is, one of my recent interviews with, Cody Ochs or Ed- Eduardo Gomez from Venezuela, and one of the questions I asked him was, \"How come people aren't using stablecoins in Venezuela?\" Right? And I think one of his answers was around education as It is actually that over time, more and more people will use stablecoins and Bitcoin becomes like, if you, if you really push it to the extreme, right? If everyone just uses stablecoins where they need US dollar, Bitcoin really does become the savings technology and that is where it has that unique advantage that nothing else can really beat."
    },
    {
      "speaker": "nvk",
      "time": "01:25:43",
      "start": 5143.84,
      "text": "Well, I, I mean, you, you know, we get to a point that you're essentially financializing Bitcoin, right? You know, you add more counterparty risk because of, you know, whatever you're trying to do, but What's nice is that we kinda go back to a gold standard in a way-ish, it's just financialized, right? Like the ultimate settling asset is gonna be Bitcoin. A-a-and, a-and still Bitcoin, Bitcoin wins, right? Like either way you wanna play this out, right? But I think it's important not to try to pigeonhole people into a volatile currency for their stable needs, right? People have stable needs, especially people who actually need their money, they don't have extra money, right? So if you are in a poorer country, right? It's gonna be a lot harder to use Bitcoin as a currency because it's volatile. So if you have little money and Bitcoin moved a lot that day, you might have extra little money now, right? And, and, and you don't have a buffer, right? You just don't have enough capital for you to play out volatility. like, you know, us in developed countries have, right? I mean, we can deal with some of that, some of that, up and downside risk, because we just have more money available. we have credit, right? So credit is a huge, facilitator of playing out this kind of risk. If you are in a foreign country, you don't have access to credit, but, or if you do, the interest is just insane, right? I mean, I remember credit cards in Brazil. I mean, it, it's, it, it's essentially unusable, right? and you can't build a business without credit. Right? People forget that. It's like you just don't come out with like a pot of gold, and that's how you start your business, right? You, you actually need to borrow or you need net thirty, net sixty days, In Bitcoin, you don't know what the price is gonna be."
    },
    {
      "speaker": "stephan",
      "time": "01:27:47",
      "start": 5267.49,
      "text": "Yeah, that's a good point as well. Like the trade credit aspect, I anticipate will still exist, right? whereas the, you know, business lending that exists today will be a lot less in the Bitcoin world. but it'll take some time to get there, right? And, you've been around for a while, obviously. You, you were doing, you know, all this coin kite stuff back, back in the day, right? Even before doing this current round of stuff with, you know, seen the cycles and the ups and downs come. Do you have any suggestions for listeners who are a little newer on how they, should think about, you know, these cycles that are just coming and going? Is it just, you know, you just have to have patience? Is that the main message?"
    },
    {
      "speaker": "nvk",
      "time": "01:28:28",
      "start": 5308.54,
      "text": "Yeah, I, I mean, you know, it's, the Bitcoin took thirty years to deliver groceries to me, right? It, it promised groceries on the first day, it took thirty years. So, I think sort of improving money, substituting money, it's gonna take longer than it did to substitute improved information, right? So, I, I honestly think that the internet was a much simpler problem and a, and a much less, It, it-- there's a lot less inertia, there was a lot less inertia, right? Because it's not like the, the libraries were trying to put you in jail because you were trying to, to have, to write an essay on the internet, right? when you're doing money stuff, you're, you're fighting, you're, you're fighting inertia, a-and, and that's a much harder problem. So, I think it's gonna take a lot longer than people think it's gonna take. I think that if you're early, you're gonna, you're gonna make a lot of money for yourself, in this whole thing. i-it's, it's the nature of being early and, and, and, and incurring more risk, right? It's just, just how it works if you're earlier on a stock, y-you know, eventually if that company does well, you, you make good money, right? So, so that Bitcoin has a lot of that. I think that, i-it's, it's, I don't know, I'm very binary in terms of Bitcoin, sort of, i-it's like Bitcoin either does extremely well or it goes to zero. there is no place to go with a deflationary currency. And, and, listen, it's like, you know, it's possible that something better comes out. E-E-E, you know, Ethereum isn't that. That's why, you know, it's funny, 'cause, you know, conceptually, yes, right? Like, there could be way better stuff out there that comes out, that does the job better, it really hits the spot of the market in the way that it needs to, and it overtakes Bitcoin, right? It's just that all the stuff that says that is that right now is none of that, right? They don't really do anything that needs to be done. so I, I don't think we could ever be complacent in that, right? Like this is a, i-it is a fight kind of system, right? I mean, you are trying to take value from another system, So, so that's sort of where I am at in terms of thinking Bitcoin in the future is just, you know, if you wanna partake in this, you're gonna have to understand risk and understand risk well. Otherwise you're gonna lose your pants."
    },
    {
      "speaker": "stephan",
      "time": "01:31:16",
      "start": 5476.03,
      "text": "Right? Yeah, great way to, summarize it. so look, I think we'll finish it up there. where can the listeners find all the information? I guess, off the top of my head, here we've got, ckbunker dot com and we've got coinlight dot com and, your Twitter as well, n v k. Anything else you wanna point out?"
    },
    {
      "speaker": "nvk",
      "time": "01:31:35",
      "start": 5495.88,
      "text": "no, that's"
    },
    {
      "speaker": "stephan",
      "time": "01:31:38",
      "start": 5498.5,
      "text": "it. oh, that's it. I'll make sure you Stuff, but anything else?"
    },
    {
      "speaker": "nvk",
      "time": "01:31:45",
      "start": 5505.21,
      "text": "Yeah, well, just, just try out Bunker and let us know, and oh, join the Telegram, the Coldcard Telegram is great, there's a lot of help there, and help us improve documentation. That's it."
    },
    {
      "speaker": "stephan",
      "time": "01:31:59",
      "start": 5519.63,
      "text": "Fantastic. I'll, I'll put all the links in the show notes, but, thank you again for joining me, Rodolfo."
    },
    {
      "speaker": "nvk",
      "time": "01:32:04",
      "start": 5524.09,
      "text": "Thanks for having me. I need to win this and get in one more time."
    },
    {
      "speaker": "stephan",
      "time": "01:32:08",
      "start": 5528.66,
      "text": "So subscribe to the show, get the show notes, and see the transcript at stephanelivera dot com slash one fifty two for this episode. Thanks, and I'll see you in the citadels."
    }
  ]
}
