{
  "episodeId": "SLP182",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "nick_neuman_jameson_lopp": {
      "name": "Nick Neuman & Jameson Lopp",
      "role": "guest",
      "tag": "NICK"
    },
    "guest_2": {
      "name": "Guest 2",
      "role": "guest",
      "tag": "GUEST"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.52,
      "text": "Hi, you're listening to the Stefan Livera podcast. A show about Bitcoin and Austrian economics. Today for episode one hundred and eighty-two, my guests are Nick Neuman and Jameson Lopp, CEO and CTO of Casa. This show brought to you by Swan Bitcoin. If you're in the US, you should absolutely get your auto-stacking on with Swan. The process is so simple, even a no-coiner could do it. There's three steps: one, auto-fund the USD from your bank account; two, auto-stack your Bitcoin; three, auto-withdraw your Bitcoin to your cold storage. Swan doesn't charge withdrawal fees, they want You to follow Bitcoin best practices and hold your own keys. Swan crushes Coinbase fees for recurring buys by up to eighty percent and beats Cash App fees by up to fifty-seven percent. Set it and forget it, enjoy your life, just Swan and chill. Go to swanbitcoin dot com slash livera to start auto-stacking with Swan today. Next is Unchained Capital, Bitcoin financial services, empowering you with financial freedom and control using multi-signature. If you're still on Signal Signature and you want a way to easily get multi-sig going, check out Unchained. They offer two of three multi-signature vaults. You can geographically separate your keys and secure your Bitcoin for the longer term. It's easy to sign up, they've got a web sign up, you can use Trezor or Ledger. Also, if you want a loan, if you want USD and you don't wanna sell your Bitcoin, you can put up some Bitcoin, it's stored on chain, it's in a dedicated multisig address, and it's never rehypothecated, and in that model, you still hold one of three keys. Make sure you check Have you got any pre-coiner friends who you're struggling to teach about Bitcoin? Check out bitcoinlessons dot org. Education around Bitcoin still has a long way to go, most people just don't understand money, so it's hard for them to think about why Bitcoin is better. Bitcoin Lessons is a Duolingo style process where people can just learn in little bite-sized pieces, whether that's five minutes or hours. I've played around with the app and I found it really interesting the way it's all structured in terms of the quizzes and the lessons and the way it teaches you, and it actually starts by teaching Interesting as well. So make sure you go and check it out, it's bitcoinlessons dot org, and you can also find it on the Apple App Store and the Google Play Store. Next is the Cipher Wheel being produced by CipherSafe. So if you've invested in a Bitcoin hardware wallet and you've got that twelve or twenty four word seed, are you backing it up? Is it fireproof? Is it waterproof? Are you just using that little piece of paper that you get with it? Well, what would happen if your house went up in fire? Look into the Cipher Wheel. It's compact, it"
    },
    {
      "speaker": "stephan",
      "time": "02:41",
      "start": 161.16,
      "text": "So it's made to be corrosion resistant and resist oxidization. So make sure you go and check that out so that your loved ones have access to your bitcoins if an accident occurs. You can also buy a casino dice or a padlock sized for it also. Go and order yours at ciphersafe dot io. Nick and Jameson. So thank you guys for joining me. And, so Jameson, I think my listeners are already very familiar with you, but Nick, you're the new CEO of Casa. I think, maybe just, tell us a little bit about yourself."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "03:10",
      "start": 189.95,
      "text": "For sure. And thanks for having us on, Stefan. So, I started out my career actually in finance, doing investment banking and private equity, and eventually, you know, kind of merged that with my excitement about tech, and that's how I really got interested in Bitcoin. And so, been-- I've been at Casa really since we began at the beginning of 2018, and, have been running product that whole time, and then for the last six months, we made the announcement In January that I was, taken over as CEO. And so since then, things have been going super well, excited to, continue building, you know, the future of self-custody for the Bitcoin community."
    },
    {
      "speaker": "stephan",
      "time": "03:53",
      "start": 232.56,
      "text": "That's great, and I, I really, I'm a fan of Casa. I think you guys are doing a great job in terms of making it easy for people to use Bitcoin, but in the way where you are holding your own keys, and that's a very important aspect of Bitcoin. so I think it'd be good to just chat a little bit about some recent updates. I saw you guys recently put out the Casa wallet, so can you tell us a little bit about that and, some of your thinking around why you've introduced the Casa wallet, which is distinct I guess kind of distinct from the Keymaster product, can you just tell us a little bit about that?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "04:26",
      "start": 266.14,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "04:27",
      "start": 266.86,
      "text": "So"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "04:27",
      "start": 267.12,
      "text": "Casa Wallet is actually part of the Keymaster app, and it is just the free version of that. And so, you know, people can actually, i-if you're an existing Keymaster user, you can use the Casa Wallet as a really easy Bitcoin wallet on your phone to hold a smaller amount of Bitcoin. So the, the idea behind the Casa Wallet is that we wanted to give people a very easy way for them to get- started with holding their own keys. People, don't quite understand, you know, somebody who's on Coinbase, it doesn't necessarily always click for them what holding your own keys means. And so we've actually built a lot of features into Keymaster to help people better manage and understand private keys. So you can do things like do a health check of a private key to make sure that it's still on your phone's secure element. And these are the types of things that we think will really help people start to educate themselves better about how to hold Bitcoin, and we've tried to make it super simple, easy as really a first step on that journey towards self-sovereignty with the"
    },
    {
      "speaker": "stephan",
      "time": "05:36",
      "start": 335.89,
      "text": "Casa wallet. Great. And so I think many of my listeners are probably more kind of savvy themselves, but they'll wanna know this so that they know what to recommend for their friends, right? and so let's chat a little bit about the, the seedless approach, right? So Casa are famous for the, the, the seedless approach. Can you tell us a little bit about your thinking on that and, how that's implemented into the Casa wallet?"
    },
    {
      "speaker": "guest_2",
      "time": "06:01",
      "start": 360.98,
      "text": "Yeah, so we've made, you know, a number of interesting trade-offs and decisions over the past few years, some of which have been controversial. we've been trying new things that haven't been done before in the space, and really one of the foundational principles that we landed on when we were originally architecting the multisig three of five Casa product was that when we tried to think through secure storage of that seed phrase, and, you know, how would we get users to be able to back this up, in a secure, robust manner that was also user friendly? It was just adding an incredible level of complexity and friction to the entire user experience. And this, this is something that has always really been taken for granted of, oh, you have to write down your seed phrase and keep it in a safe place. But when we started thinking, outside The box and, and thinking, you know, well, what if we could somehow completely get rid of this aspect of maintaining, your own funds, then we can simplify the, the whole model en-enormously and get rid of a lot of potential threats and attack vectors. So Within the multisig setup, we created this idea of being able to rotate out your keys and your devices, natively within the app with a very simple workflow. And once we were able to do that, we realized that, you know, if you can rotate out the keys, with just, you know, a f- a few taps of your finger and going and getting hardware devices, then this means you have essentially created a self-healing type of setup. Where you don't need to go dig out a seed phrase from somewhere and reconstitute your, particular hardware device, but rather you can just replace it completely in a secure fashion, by creating a Bitcoin transaction. Taking that a step further, when we were trying to figure out, well, how do we do seedless for a single sig setup where you can no longer do that rotation, we basically landed on, well, how do we create a, a backup that is kind of- Kind of like multisig, and, and essentially we encrypt the seed phrase and put it in your, the user's, iCloud or Google Drive or, you know, whatever native data storage they have on their phone and Have the encryption part, the, the part that would actually decrypt that, then stored securely on Casa's server, additionally encrypted with our hardware security module. So what that essentially does, it creates like a two of two type of multisig if you want to reconstitute that seed phrase, and it means that, you know, Casa still never has the private key data, Apple never has the private key data, Google never has it, you know? requires essentially, two factors in order to reconstitute it securely on your phone."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "09:12",
      "start": 552.39,
      "text": "Yeah, and what we, what we realized around Seedless was that Taking Bitcoin from the current core community to the next, you know, million people, the next hundred million people Eliminating seed phrases as a point of friction is one way to really help with that, because if you think about, you know, or if I think about my mom trying to use a seed phrase, for example, she can barely keep track of her passwords, so how is she gonna keep track of this twenty-four word phrase that actually protects her money? And if she loses that phrase, her money's gone forever. That's just not gonna fly. And so figuring out how to take down some of these barriers Barriers for people is one of the reasons that Casa exists."
    },
    {
      "speaker": "guest_2",
      "time": "10:02",
      "start": 602.24,
      "text": "And, part of the, the friction there, of course, is, it's just, it's IT, data management, techie stuff, is that if we consider private keys and seed phrases to be kind of like, hazardous, toxic waste, the vast majority of people don't have the skills or, or the time to figure out how to handle that correctly. There are a lot of people in the Bitcoin space Who have put in a lot of time and they have the skills to be able to do that. But we're looking beyond, you know, the current nerds who are willing to go through a lot more, effort in order to do things on their own. And, you know, a good example of this is actually just last week, but this, this happens all the time, someone who was using a hardware device, you know, to secure their funds as is best practice, lost everything they had because they unfortunately got- Tricked into putting their seed phrase into some malicious software and, you know, that malicious software stole all of their money. So, you know, the ability to be able to handle that data is, is a very tricky thing to do, especially when we consider that a single mistake can result in financial catastrophe."
    },
    {
      "speaker": "stephan",
      "time": "11:16",
      "start": 676.3,
      "text": "Right, and so I think that's an interesting example where if you were trying to teach your friend, okay, be careful what browser extensions you install, be careful what other, you know, X, Y, and Z, and you'd, you'd have to try and coach them through all of these different aspects where potentially, yeah, maybe there is an opportunity to simplify. so can you just walk us through a little bit of the, the Casa wallet in terms of how, how the, like, what it looks like from the user perspective when they're trying to recover, for example?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "11:45",
      "start": 704.94,
      "text": "Yeah. If they, let's say somebody has the Casa wallet on their phone, it's, let's say they're using an iPhone, and they actually lose their phone, all they need to do is get a new phone During setup, they're gonna log into their iCloud account, and so that provides one piece of the key, and then they're gonna download the Casa app, log in to their Casa app, and that provides the second piece, the decryption key. And then seamlessly in the background, the Casa app's just gonna pull down the app for-- or the key from iCloud, decrypt it using the key from Casa's server, and then immediately store that decrypted private key in the phone's secure area. element. And so the decrypted private key is never actually held outside of the secure element of the phone. But from the user's perspective, it's a very seamless, simple process using accounts that they already have and are already keeping track of. And so this is a lot less scary than having their seed phrase on a piece of paper, where if they realized they lost their phone, now they're suddenly Thinking, oh man, I hope I have my seed phrase saved in my sock drawer at home or whatever it is, you know? And so it just takes a lot away some of that anxiety. And this isn't, this wallet is really, it's a beginner wallet or it's an, a very easy to use kind of, you know, like literally the, the wallet you would keep in your pocket. And so it's not meant to store a huge amount of funds. That's why we have the multi-sig side and that's why this is all put together In one app. And so we really expect this to be, for, for new Bitcoiners, this is the first step on their journey, where then as they acquire more Bitcoin or Bitcoin goes up in value and they need more security, they can really easily move up to having a multi-sig account to secure that Bitcoin."
    },
    {
      "speaker": "stephan",
      "time": "13:48",
      "start": 828.14,
      "text": "Gotcha. And I presume then the transition from single signature Casa wallet version into the two of three is just like a smooth transition up, and they would basically buy a hardware wallet and then become a gold member? Or can, can you just talk us through that process?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "14:03",
      "start": 843.35,
      "text": "Yeah, sure. So let's say somebody is currently using Casa wallet for free, they decide they wanna upgrade to multisig, they'll buy a hardware wallet. You can either, you can buy one directly from Trezor, Ledger or Coldcard or Casa actually Actually, is a authorized reseller of both Trezor and Ledger, so you can buy one from us if you want. And then the process is, you, you know, you sign up for the gold membership, upgrade your account, you'll see that new multisig keyset in the Casa app, and you can simply send, you, you set that up with your, hardware wallet, which is a really easy process, and the app guides you through all of that. And then you just simply send the funds from the Casa wallet single signature feature to the new multisig that you just set up. And you, you'd still, at that point, you still have access to the Casa wallet. So let's say you wanna store the majority of your, your Bitcoin in your multisig savings account, and then the Casa wallet's just like your checking account for when you wanna, you know, put some money into that poker game or something like that."
    },
    {
      "speaker": "stephan",
      "time": "15:10",
      "start": 910.18,
      "text": "Right. also there was some discussion online about the question of a wallet being open source. So did you guys wanna address any of that and just discuss, how you're thinking about the question of closed source versus open source in, in a Bitcoin wallet?"
    },
    {
      "speaker": "guest_2",
      "time": "15:27",
      "start": 926.96,
      "text": "Yeah, I mean, this is something that we've talked about, you know, ever since we started the company, the, the various trade-offs between what you can accomplish with free open-source software, versus, you know, a for-profit company that may not, open-source all the software that it's writing. And when you're looking at the multi-sig product that we've built That is actually a, a very well diversified product, because you end up using, open source software, you know, firmware and hardware from a variety of different, companies, which helps you both, increase your level of security, from a, a variety of different threats, and, decrease the likelihood that, you know, all of those different actors out there have been compromised and will, you know, coordinate to work against you. It gets a little bit trickier, you know, when we're talking about a, closed source single sig hot wallet. I mean, this is a riskier threat model, there are more ways that you could lose, the money. There's, you know, more, more potential catastrophic threats, and that is why it is only really meant for small, values. But, you know, the, the trade-off is you have a much more user-friendly experience, because Because the user doesn't have to go get any specialized hardware, you know, it's all just there on their phone. Now, when we're talking about open source versus closed source in the context of mobile apps Then it gets even trickier because it is difficult, if not impossible, in fact, we have not yet really found a way to verify the build of a mobile app that is on the Apple Store or the G- Google Play Store. The, the way that these mobile app stores work is that they require the applications to be cryptographically signed by the developers in order to get- pushed out to the store, but the actual build process for the app, the actual, you know, attestation of what the code that's, that's being run on the app is not really a part of the experience that, Apple and Google provide. the only real option if you wanted To be sure of what the actual code was that was running, is you would end up having to build the mobile app yourself and load it onto your phone. This is, you know, theoretically possible at least with Android, but it requires a fair amount of technical experience. It's really not the, the, the people who have the ability to do that, we are not really targeting them, for this experience. You know, this is meant to be for non-technical, people who are very early. in their Bitcoin life cycle. So it really seems like from a, free open source software, security side of things, that it, it's more of a feel good idea of having open source mobile apps if you can't actually verify. I mean, we're all familiar with the mantra of don't trust, verify, and if people could, you know, verify that the code we open sourced was the, the code that was is out there on these stores, then I think it would make, you know, a stronger argument for us to be open sourcing it. The other downside is that, like I said, these apps require, cryptographic signatures from the developers, to be on the store. There's also various functionality that we're using, such as some of the pieces of the seed backup that also require that. So even if you built the app on your own, you wouldn't have a fully functioning Casa wallet, you know, the user experience Experience that we really intended. So there's trade-offs."
    },
    {
      "speaker": "stephan",
      "time": "19:28",
      "start": 1167.74,
      "text": "Yep, yep. I think that's a totally fair point, and I've seen some discussion amongst the community about things, so you might have seen that project, I think it's wallets scrutiny, and so the idea is, oh, okay, it's not verifiable, but I think for the same, for those same reasons that you mentioned, it might be it might not really be such a fruitful exercise if you can't really verify anyway because of certain things that are getting inserted, inserted into the process either on Google's, Play Store or on the iPhone or Apple App Store also. So I think that's a, it's a fair point. I suppose the, the other concern is more just around being able to recover, right? So as I understand, for the paid product with Kasa, you have sovereign recovery. Does such a system exist or can it exist in the- The single signature version or is it more like only keep small amounts on this wallet? What's the thinking there?"
    },
    {
      "speaker": "guest_2",
      "time": "20:19",
      "start": 1218.88,
      "text": "Yeah, so we actually do have, you know, sovereign recovery process for the single signature mobile wallet. It is a bit different, you know, instead of having, various public key data that, that you store ahead of time or, or get out of the app and use to, you know, recreate your wallet using other software, we actually have The ability to export that seed phrase. And under normal conditions, if you go in and you tap on the key and you go through the process to export the seed phrase from your Caso wallet, we will actually mark it as compromised because we assume, you know, we can no longer be sure that that seed phrase hasn't been, taken by an attacker, and so we, we no longer allow you to use those keys within the Caso wallet. If For example, Casa blew up and our, our service ceased to exist. As long as you still have the app on your phone, we also have, you know, offline login ability, so you would still be able to authenticate locally with the Casa wallet, log in, and go through that seed phrase export process. And, you know, we have the instructions available on walletsrecovery dot org and also, within the app you can And actually get these sovereign recovery instructions emailed to you that give you a step-by-step guide of, you know, how do you recreate your wallet without using Casa software, without using our service, and be able to, you know, recover from even an extreme disaster scenario where we no longer exist?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "22:03",
      "start": 1323.02,
      "text": "Yeah, and just the, on the point of, you know, where we actually mark that key as, as compromised. So the point of that is actually just to give people a, the heads up that, hey, this key was exported, and you should generate a new key if you're gonna continue using the Casa wallet. And so that's, that's all that that does. And so then, let's say you, you say, \"I'm gonna export my seed phrase to use a different wallet,\" but then you change your mind or something like that, and you say, \"I'm gonna ke You can just generate a new key, the app walks you through that, and then it'll let you just transfer the funds from that previous key to the new key, and so that then lets you fully use that key again and is a key that is ensured that the seed phrase for it isn't floating around out there somewhere. and obviously, you know, if you, if you didn't wanna continue using the Casa wallet or you exported the seed phrase in order to use another, a different wallet, you would have full control over those funds once you imported that seed phrase."
    },
    {
      "speaker": "stephan",
      "time": "23:05",
      "start": 1384.68,
      "text": "Gotcha. And, also, so, I mean, you mentioned earlier that, this is basically, it's all happening encrypted. But is there any sort of concern that, you know, around things being stored on Google Drive or on Apple iCloud or is it just more like you think that, that was kind of the, the best way to balance that trade-off there? What, what was the thinking around that?"
    },
    {
      "speaker": "guest_2",
      "time": "23:26",
      "start": 1405.92,
      "text": "So all that, Google or Apple even sees is this, I believe it's a hundred twenty-eight bit blob of data that, it, it, it means nothing to them, like they cannot interpret it as anything sensitive because it has been encrypted. The, you know, potential adversarial scenario is, okay, well, you know, what if Apple and Casa colluded, to, you know, come together to decrypt this? Data, you know, that could be a potential adversarial scenario that, that people are thinking through, and it's, you know, a good, an, another good reason why, you know, you should really only be keeping, you know, pocket money, in this type of setup. It is, it is not as robust against, various types of loss as the multisig hardware-backed, offerings that we have."
    },
    {
      "speaker": "stephan",
      "time": "24:19",
      "start": 1458.53,
      "text": "Yeah."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "24:19",
      "start": 1459.29,
      "text": "Yeah, that's a fair point. go on, Nick. I was just gonna say that, yeah, and to, to add on to that, we obviously don't collude with Apple. I'm not going to be calling up my, my bud Tim Cook and saying, \"Hey, I need to get this mobile key, man. You gotta help me.\""
    },
    {
      "speaker": "stephan",
      "time": "24:37",
      "start": 1477.2,
      "text": "That's right. also, I think, I, I guess just for my listeners as well, they wanna be thinking, okay, I wanna select the right tool for the job, right? So depending on what, if they're trying to help a new, you know, Bitcoiner, they've gotta think, what are they trying to do, right? So if they wanna set up, you know, a BTC Pay and they need like an xPub to go into that, well then Castleville's not the right choice for them. But if they're trying to set up a person who's"
    },
    {
      "speaker": "stephan",
      "time": "25:07",
      "start": 1506.68,
      "text": "Right, like the right tool for the job. Would"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "25:13",
      "start": 1512.9,
      "text": "you say that's kind of the, the right, target that you're going for here? Yeah. Yeah technical, that right now you wouldn't feel comfortable referring them to most of the self custody wallets that are out there because you're worried that they might lose their funds by making a mistake. And so instead, you're saying, \"Well, you're only doing a couple hundred bucks of Bitcoin, so just use Coinbase, you know, that's, that's easy, and they won't lose it for you.\" This is for that type of person who really wants to take that first step into self- Sovereignty, but they're just so far at the beginning of their Bitcoin journey that it doesn't make sense for them to go into this super long technical rabbit hole. So we'll guide them through that, they will learn over time, and then they'll be able to take more and more control as they actually learn what's going on."
    },
    {
      "speaker": "stephan",
      "time": "26:27",
      "start": 1587.37,
      "text": "Yeah, and I think this is an interesting point as well, because obviously within Bitcoin, we love to have a good debate, right? And so one of the big debates is around sort of purity testing and how, how hardcore are you, and are you doing it literally every step on your own? And then it's sometimes we have these kind of internal debates amongst our kind of Bitcoin world of, \"Oh, this isn't fully open source, and you're not fully doing everything yourself.\" and then the person who's trying to provide a sort of ramp up for, let's say, newer- Bitcoiners, they, they can get attacked a little bit, right? And so we sort of have this almost like a spectrum of like fully self-sovereign and then leaving it all on a large exchange, right? Yeah. And so, so, so the people trying to offer an in-between to try and, bring them along that pathway, sometimes they get attacked a little bit. Is that, is that some-- is that sort of a tension that you face, or is that essentially the position you're in? You're trying to guide people through?"
    },
    {
      "speaker": "guest_2",
      "time": "27:23",
      "start": 1642.59,
      "text": "Every day."
    },
    {
      "speaker": "guest_2",
      "time": "27:27",
      "start": 1646.63,
      "text": "To see, I think one of the more interesting aspects of entrepreneurship, and I don't know if this is more, limited to, to our industry or what, but, it's very interesting to have lots of people, coming to you and explaining to you why they aren't your target market. that's essentially what it, it boils down to, is that, we realize, you know, the capabilities that, that Bitcoin, makes of- available to people, especially if you have additional skills or you're willing to invest additional time to gain the skills required to essentially do everything on your own. You know, this, this works for, for both the privacy aspects and the security aspects of, like, you're never going to be able to be, you know, the maximum level of privacy and security if you spend a ton of time doing everything yourself. The trade-off There is that, who's gonna help you, you know, if you screw up or if you need to understand some obscure thing? You end up having to use community resources, you know, if you're using free open source software, the level of support is community based. there's, you know, there's no one out there who owes you an answer to anything, and so it's a much, trickier type of environment if you're trying to, in, you know, improve your Understanding, and I, I put a lot of resources out there to try to make it easy for people to improve their understanding, but at the end of the day, I think that a lot of people find value in having some experts that they can just call on the phone or shoot an email to and very quickly get a, a response back so that they don't have to go searching through a whole bunch of knowledge that's spread all over the internet."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "29:22",
      "start": 1761.58,
      "text": "Yeah, and, and just thinking about that ramp of getting people to the point where they're fully self-sovereign, you know, the, even the people in the existing Bitcoin community didn't start off their Bitcoin life unless they're just, you know, the most hardcore of the hardcore, maybe Adam Back or something, like they didn't start off their Bitcoin life as the fully self-sovereign version, right? You have to start somewhere. And so in order to bring- Bitcoin to the rest of the world, we have to make some interesting trade-offs, but like what we're, where we don't compromise is on people hold their own keys and we aren't trying to, you know, track people or sell them ads or trick them into doing strange things with their Bitcoin. We just wanna give them a safe place where they can learn how to be their own bank, and that's our, that's our goal. And so- On our way there, we're, we may kind of rub some people the wrong way, but in the meantime, we'll do our best to keep building."
    },
    {
      "speaker": "stephan",
      "time": "30:29",
      "start": 1829.22,
      "text": "Right, and I think, that's a, a, a good goal and a good way to proceed, and I think that makes a lot of sense to me. also wanted to chat a little bit about the focus this year with Casa, as I understand, the focus really is on, you know, this wallet and the keymaster aspect as opposed to the node. Could you just outline a little bit around that and what your view It was quite popular, but, it seems to me like the focus with Casa is more towards the keymaster and the multi-signature part because you wanna sort of nail that part down first. Is that how you're thinking about it?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "31:03",
      "start": 1862.9,
      "text": "Yeah, so we, we really at the very end of last year, beginning of this year, we sat down and said, okay, we're, we're still a small company, we're still growing, how do we have the best impact for the Bitcoin community as a whole? And we realized that this problem around people- Self-custody in their Bitcoin was still not fully solved, and it was big enough in that every single Bitcoiner has to deal with this. And so let's focus all of our attention on making this as easy and as doable as possible for everybody, and then we can move on to solving other problems in the future like how do you run your own node, how do you, you know, the other steps that you can take kind of along the Bitcoin- Journey, but this we really identified as a need for every single person who has Bitcoin. and so that's why we just wanted to focus our full team's efforts on that. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "32:04",
      "start": 1923.78,
      "text": "And I presume then the idea is that in future you would look at ways potentially to try and have it all sort of connect back to your own node. Is that something that you would explore?"
    },
    {
      "speaker": "guest_2",
      "time": "32:13",
      "start": 1933.23,
      "text": "So there's multiple tiers of sovereignty, right? And so, you know, the first step, which is what we're doing with Caswalla, is just getting your keys off of third party services and, and taking custody. You know, I would say the next step is starting to use hardware devices, you know, create air gaps, so- So that you're protected from a variety of online threats. The next step is using multisig, you know, geographically dispersing your keys so that you're getting additional robustness both against attack and against loss and disaster. And really like the final step in, you know, being self-sovereign in Bitcoin space is you've got an extremely robust setup for your private keys and then you're validating whatever transactions you're receiving to ensure Sure that you have that model of trustlessness where you're not having to ask anyone else, what the truth is, you know, what the actual value is that you're receiving. So it's definitely, it's, it's always been a long term thing. We may have jumped the gun a little bit, tried to get there a little too early, but it's definitely still, you know, something that we hold, dear as a value."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "33:26",
      "start": 2005.75,
      "text": "Yeah, and the whole team is excited about offering people the ability to connect their keymaster to their own node. I mean, that's something that everybody has wanted to do from the start. And so as we think about this, you know, whether it's, it's still important for us and we want- To give that to our customers. And so whether that's with the Casa node specifically or maybe it's just connect to any, Electrum node or, or something like that, like we wanna figure out how to get this done, and it is something that we'll, we'll work on. So that's, like Jameson said, that's kind of the apex of, of fully sovereign Bitcoin, and so we, we do want to help people be able to do that."
    },
    {
      "speaker": "stephan",
      "time": "34:11",
      "start": 2050.88,
      "text": "Fantastic, I think that, yeah, makes a lot of sense to me. also, I was keen to discuss what you guys thought about, well, I'm sure you have some thoughts on this, the Trezor, aspect. Well, I mean, it's not just Trezor, it was the, I guess, just for detail and background for the listeners, there was a Basically a bug in BIP one forty-three, and I think it was first actually noticed by Greg Sanders in like twenty seventeen, but the recent aspect of this happened when Saleem Rashid, a hardware wallet researcher, disclosed a bug in, it like basically exploiting that bug in a way that could essentially, be a problem for hardware wallets, and then, as I understand, that caused kind of like these downstream impacts because Trezor, on their end, tried to fix it up, but the way they Fixed it up, made it more difficult for other players in the industry, such as BTC Pay and potentially for yourselves. Did you want to just comment a little bit on that and whether that was made more difficult by using the seedless approach, but essentially, yeah, essentially what was your thoughts on that?"
    },
    {
      "speaker": "guest_2",
      "time": "35:13",
      "start": 2112.62,
      "text": "We were Certainly affected by the changes. I mean, whenever firmware changes happen, there are potential impacts there. seedless isn't really so much of an issue. the only time that sometimes becomes an issue is firmware updates that are so major that they're like rewriting all the data on the device and, and potentially wiping it out. And, and in those cases, you would actually be able to use our, our key rotation mechanism in order to update a device. That, was completely out of date. But, you know, really like the bigger impact that it had with us was that Trezor was making some changes, without, you know, talking to the rest of the community and, you know, potentially breaking changes, we had some other issues as well that were actually unrelated to the, the vulnerability in question. My main problem was that this vulnerability is an extreme edge case, like it requires that your wallet software be malicious in the first place in order to try to get you to, to re-sign, the same UTXOs multiple times. So like it re- it actually requires, you know, multiple, Types of, of attacks to, to happen at the same time, at least if it was going to affect like a Casa, multisig, that is on multiple different hardware devices. So it just seemed like, pushing out potentially breaking changes for such, an edge case was not really warranted, as far as I'm aware, like we've never seen any attack like this actually be executed in the wild. But, that is part of Of the fun, and dynamic security space that we're in is that, you know, people can make decisions that, that affect other players in the space, especially when you're essentially building a platform, you know, that other people are building on top of, and I think that's what has, created a bunch of contention here is, Before recent times, Trezor was probably more of a monolithic entity, where, you know, they're creating their hardware and their firmware and their software apps, basically the whole stack was mainly, you know, Trezor, Trezor, Trezor. But now as Bitcoin ecosystem has grown, more people, more entities, such as ourselves, are using these base level, you know, hardware devices as platforms. So it, it actually kind of- becomes like Bitcoin protocol development, right? Is that, you have so many, potentially like unknown consequences to your decisions and your actions, things that may be affected by changes that you make, that you, if you don't wanna piss people off, you need to start being, a lot more conservative and conscientious about every little change that you're making."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "38:24",
      "start": 2303.54,
      "text": "Yeah, and the, the Trezor team's been talking to us about this and, and talking about how we can get some of these, the issues that cropped up fixed, and so they've been helpful there. And, you know, it, like Jameson said, it, it adds a whole lot more into their development model when they have to start thinking about everybody that's building on top of Trezor in the ecosystem. which on the one hand is great because it shows the adoption of Trezor and that they've, you know, built something great that a lot of people use A tough situation for them, so definitely understand the, the place they're in too. and the thing that I come back to though, just thinking about hardware vulnerabilities in general, is that you-- this is one of the reasons why you wanna use multisig, because if you had a vulnerability for a Trezor and that was your only key securing all of your funds, then maybe you're in trouble. But if you have a vulnerability on a Trezor that's one of five- Keys, two of the other keys are a ledger, a cold card. You know, you have actually a lot more redundancy and a lot more security just from having a more diversified hardware model like that. And so that's one of the thing, one of the reasons why multisig is such an, an interesting and important, way to secure large amounts of Bitcoin."
    },
    {
      "speaker": "stephan",
      "time": "39:46",
      "start": 2386.35,
      "text": "Yeah. And are you also looking at any other hardware wallets out there? Are there any other ones that you're interested in potentially adding as an option, or is it sort of like none of them are really mature enough yet? What's the thought there?"
    },
    {
      "speaker": "guest_2",
      "time": "39:59",
      "start": 2399.48,
      "text": "It is a dynamic space for sure, and you know, we're constantly staying on top of these things. I mean, I am aware that there are a number of, you know, projects out there that we're hoping we'll see drop, basically before the year is out. And, you know, as these new hardware devices come out, we'll be evaluating them, trying to figure out, you know, if we can use them to increase the security, increase the usability of our system. So I am, I am definitely- I'm really excited to see new types of hardware come out because I'm sure that they are going to make new decisions on various trade-offs, and we're gonna get to play around with them and figure out, you know, What can we leverage in order to make a better Bitcoin experience for people?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "40:49",
      "start": 2449.19,
      "text": "Yeah, and one of the interesting things that we've been talking about is some of the wallets out there are working on like a fully air-gapped QR code based on a screen way to sign. And so, you know, instead of plugging in your Trezor or Ledger directly to your computer to sign something, you can actually transfer transaction data between a mobile app and a hardware wallet using QR code Codes. And I, the like one team that's working on this is, Foundation Devices. And so, like, there's some really interesting models that are starting to come out around there, which we will definitely be, looking into and figuring out how to integrate with Cosmos."
    },
    {
      "speaker": "stephan",
      "time": "41:31",
      "start": 2491.06,
      "text": "Great, and yeah, I presume with most of these things, it just takes time for the wallet and the method to be established. And, you know, I think, for example, with Coldcard, there was enough of a community around who-- people who wanted Coldcard, and I suppose that was also part of the driving factor to try and, bring them in. also, I think an interesting point is just around, coming back to when you're doing a rotation or, if there is a vulnerability or if there's some kind of firmware update, I guess the important"
    },
    {
      "speaker": "stephan",
      "time": "42:01",
      "start": 2520.58,
      "text": "That you might want to, let's say, check all of your keys before updating one of them, right? Could you just expand on that idea?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "42:10",
      "start": 2529.53,
      "text": "Yeah, so we have the ability within Casa where people can do a health check, like I said earlier, and what this lets you do is say, okay, is the private key that matches this wallet still on this device? So like, I can sign with it, it's good to go. And, you can do that for every single one of your keys. And so what we- We recommend if, if somebody's gonna do a firmware upgrade on one of their devices, they should do health checks on the other devices to make sure that they have at least three that they can be signing with in case that, firmware update wipes the device that they're doing it on then. And so then that just, you know, from an order of operations perspective, it's like practicing good hygiene of just making sure that you're fully healthy before you go undergo an operation to update your firmware and then, you know, After that happens, if, it did wipe the key, then you're, you're totally fine, and you can just use the other keys to rotate that out and, create a new wallet"
    },
    {
      "speaker": "stephan",
      "time": "43:12",
      "start": 2591.84,
      "text": "Yeah. also, I guess just more broadly in this space, I mean, we are-- I think some things happened this year that most people wouldn't-- obviously, things happened this year that most people wouldn't have predicted. So one example, and in the castle model, is multi-location. but obviously with coronavirus and the lockdowns and so on, did that? Change because people were obviously locked inside, they weren't able to go to visit all of their keys. Was that something that c-came into your own-- obviously, I'm sure it did, come into your own thought process around how Bitcoin people should be thinking about multi-signature and management of their keys?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "43:52",
      "start": 2632.31,
      "text": "Yeah, so this is one of the reasons, why multi-signature combined with multi-location is helpful, because we've had people who were, you know, maybe their key was inaccessible in a safety deposit box somewhere that was closed because of all the COVID restrictions. Well, if they really needed to move funds, they likely had access to some of their other keys or could utilize the Casa recovery key and rotate that key. Out, and so then replace it with a key that's actually under their control, and maybe they can put that in a different location that isn't closed down. and this is one of the times when having support actually really comes in handy, because we were talking with some of our platinum and diamond clients and helping them evaluate their security model and think about their key distribution, and some of them said, \"Oh, you know, I, I think it would be really helpful if you could decrease the...\" The amount of time that you wait to sign with the Casa recovery key for me during this period. And so that's some of the things that we can do just by having this really hands-on customer support team that you wouldn't necessarily have backing you up in a scenario where you're doing it fully by yourself."
    },
    {
      "speaker": "stephan",
      "time": "45:12",
      "start": 2711.71,
      "text": "Awesome. and I guess, yeah, just, kind of more broadly, just around, you know, personal security, I know that's a big focus for you, Jameson, in this age of, you know, surveillance as well. Are, are there any other kind of tips or things you're thinking about that people should be, you know, thinking about when they are looking at, okay, how do I, you know, stay kind of a little bit more secure or potentially, against, try and stay a little bit more private?"
    },
    {
      "speaker": "guest_2",
      "time": "45:43",
      "start": 2743.03,
      "text": "Really, the only thing that I think has changed in the past few months is now it's, a lot less socially awkward to walk around while having your face covered. And of course, I, I recommend doing that as much as possible. and hopefully, this will be something where, you know, we'll see a culture shift to be more like, you know, Asian cultures where it isn't frowned upon or considered odd. To be walking around with a mask."
    },
    {
      "speaker": "stephan",
      "time": "46:13",
      "start": 2772.57,
      "text": "Hahaha. Did you have any, tips for the listeners out there,"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "46:18",
      "start": 2778.03,
      "text": "Nick? You know, I, I tend to leave the opsec tips to Jameson because I go to him for all of my opsec questions, so, you know, I don't have too much to add there, I'd"
    },
    {
      "speaker": "stephan",
      "time": "46:29",
      "start": 2789.0,
      "text": "say. Sure, sure. and look, I think part of it is also just w- once you start on that journey, right? Because I think people can be a little bit too, what's the word? Like, disheartened or not willing to even start. But if you like, at least try and take one step at a time, you can slowly, regain or at least try to reduce the impacts to your own privacy and some of your own security. And I, I think that's another thing, to your credit as well, with the Casa team, you've got the So, tell us a little bit about what you've been sharing in, in the recent security updates."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "47:06",
      "start": 2825.68,
      "text": "Yeah, so we, we have a security newsletter that goes out every week and talks about not just, you know, Bitcoin security, it talks about lots of, data breaches, it talks about privacy and general cybersecurity problems that may be coming about due to the situations in the world or decisions that companies are making. And so- So the way that we view that newsletter, and you can sign up for it on our website, is just a really, a helpful rundown of the most important security news from the week. And there's not a lot of the, these out there, you know, you might kind of catch stuff here and there, but, we're trying to really just compile this for our subscribers, and that it comes with our quick bullets of, \"Hey, here's what you should be thinking about with re- Regards to this specific story. And so, you know, that's something that not everybody knows what to-- like, they may, they may see an article that talks about a data breach, and they may not actually know what to do after that to ensure they're safe. And so we'll put a few bullets in there that is like, \"Well, you can go check on Have I Been Pwned to see if yours was, your, information was included as part of a data breach, that kind of thing. \" And so it's just an, an extension of- Of what we do with helping people manage their keys and their Bitcoin security into helping people manage their general personal and cybersecurity."
    },
    {
      "speaker": "stephan",
      "time": "48:41",
      "start": 2921.01,
      "text": "Yeah. And, also, I think some of the focus now, I'm slowly starting, I'm starting to get more awareness myself on some of these other projects of things like, so for example, instead of having Google Drive and Google Documents, you can have something like NextCloud, right? Like a self-hosted, you know, office, things like that. Are these also aspects that, you at the Casa team would be looking at, talking about, or, trying to teach your subscribers around those elements as well?"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "49:12",
      "start": 2952.0,
      "text": "Yeah, and one of the things that we-- so we like these services, one of the, the problems with them right now for, especially for some of our user base, is that they're still a bit hard to use, and there is definitely-- I mean, we see this with Bitcoin key management as well, there's a significant convenience barrier. So unless you can make it as convenient or more convenient than the existing services, it's gonna be really hard to get people to switch Switch. And so what we are really excited about though is, is seeing these types of services like NextCloud get better over time and iterate on themselves, and it's kind of like Bitcoin, you know, they've got this early community of hardcore adopters that's very technical and willing to go through the extra steps they need to take, and then, as they grow, they're actually able to build out a better user experience and get a lot more of the, you know, later adopters who don't wanna Mess with all of that early stuff. And so, I mean, a, a good example that, of a product that I think is really interesting is the Helm. It's a e- personal email server, and it was, it came out like actually right around the same time as the Casa Note, if I remember right, but I, I've got one sitting behind me on my little desk and, It was a really, it was a much simpler way to set up your own personal email server than anything I'd found before, and it's all stored on a device that's sitting locally in my house. And that's something to me that is, you know, a really interesting step along this path and something that we really like to see at Casa, 'cause it- We really envision this more kind of distributed and, and decentralized future where people have a lot more control over their own wealth, over their own data, and they can do that by using some of these products like Casa or like Nextcloud or like the Helm."
    },
    {
      "speaker": "stephan",
      "time": "51:16",
      "start": 3075.86,
      "text": "Right, yeah, and I, as I understand as well with, email, one of the difficulties is, like you can run the email server, but then the other difficulty is not getting picked up in the spam filters of other people's email, clients, right?"
    },
    {
      "speaker": "guest_2",
      "time": "51:30",
      "start": 3089.75,
      "text": "as, as someone who spent the first ten years of his career actually working at an email service provider, It's, it's a whole hot mess, beyond just the technical issues, there's actually a lot of, social networking that goes on between ESPs and ISPs, and, and spam lists, and, it's, it's, it's definitely its own network, and trying to become a provider on that network is, it's not as easy as running your own Bitcoin node."
    },
    {
      "speaker": "stephan",
      "time": "51:59",
      "start": 3119.19,
      "text": "Maybe someday we'll get there. I think some of this stuff also reminds you the typical conversation you might hear when someone says, \"Oh, everyone should use PGP.\" And then the reality is not many people actually use PGP. Yeah. The reality is PGP is really hard to use, even for somebody that knows what they're doing. Right, and so I think the equivalent is like trying to build something like Signal, right? Something like it's kind of, it's, it's accessible to the typical consumer level and therefore will get more use, and therefore, i-in some ways, you, you, you can get a lot more scale with that, although it's not the purest, it's not the purest option, let's say."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "52:39",
      "start": 3158.93,
      "text": "Yeah, and, and maybe, maybe one day, you know, Signal's like a, a good example of a stepping stone. Maybe one day Signal will figure out a really easy way for people to actually manage their encryption key, and that's something that is, really interesting and, but it's, it's definitely not something that the majority of people are ready for right now. And so Signal, I think, is doing a great job at being one of those intermediate steps of, yeah, okay, we're getting you off of SMS where anybody can read everything you say, and getting you onto something that's a little more encrypted and, and it's even better than something like- Like WhatsApp where it's all, you know, totally, flowing through their servers and readable by Facebook. So I think Signal's a great example of some-somebody that's bridging the gap there."
    },
    {
      "speaker": "stephan",
      "time": "53:30",
      "start": 3209.81,
      "text": "Yeah. I wonder if you guys have explored any of these other messaging, apps like, like the, Riot Matrix. well, I think Riot is the client and Matrix is the protocol. I'm not sure if you guys have explored any of that as also."
    },
    {
      "speaker": "guest_2",
      "time": "53:45",
      "start": 3225.05,
      "text": "Yes, it is, one of our favorites, actually. We actually"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "53:50",
      "start": 3229.85,
      "text": "use it as a company. Yeah. Oh, there you go. Yeah."
    },
    {
      "speaker": "guest_2",
      "time": "53:54",
      "start": 3233.65,
      "text": "I've been using it, for several years. it's, you know, it's great for, you know, small team internal communication stuff. I remember at, at BitGo, you know, we, we were looking for an alternative to get off of Slack, as, as soon as possible, and it was- Great when, Matrix, you know, became stable enough to use."
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "54:18",
      "start": 3258.22,
      "text": "Yeah, and it, the, the interesting thing about Matrix and Riot is that You can tell that as a small team, it's definitely usable, and so we use it, and we kind of deal with some of the quirks. But for every new person that adds your kind of, or that joins your matrix server, if you're fully self-hosting this, like we are to be, to keep everything fully ended and encrypted, then they have to verify every other person in the company that they wanna talk to, and every person in the company has to verify them. And so when you start to talk about company- companies that are hundreds, thousands of people, this gets way harder to do. And so I know that Riot's been working on a bunch of improvements to this, and even in the two years that we've been using it, it's become way easier to verify keys with people. But getting to that next step is just another example of like, it's gonna take some time before they can really make that jump into a mass audience."
    },
    {
      "speaker": "stephan",
      "time": "55:20",
      "start": 3319.97,
      "text": "Yeah. So I guess with many of these things, I guess part of the theme here is taking stuff that used to be kind of out there in the open and trying to find ways to bring it back where you have a little bit more control, or in some cases, full control. so I guess different things will be at different places in the journey, right? So I think, you know, with, in terms of Bitcoin, w- you know, it's becoming more and more easy now to hold your own keys, but perhaps a little bit more difficult to do multi-signature on your You know, so we've got, you know, guided providers, and then similarly with things like, you know, email and other things, it just, it's, they're all kind of on this journey, but at the same time, there's kind of tension kind of pushing the other way because, as an example, there might be some new feature that comes out and, you know, everyone wants the convenience of that. So how do, how are you thinking about that? Do you think people are nowadays slowly waking up to that aspect of like, okay, I need to actually take some more"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "56:20",
      "start": 3379.97,
      "text": "I think it's, it, it's a really difficult question because it's very easy to think of this from the perspective of our Bitcoin Twitter echo chamber, where we believe everybody in the world wants to be fully self-sovereign. And, it's challenging to go outside of that bubble and even talk to your friends who aren't Bitcoiners and hear that they don't necessarily care about that. So that's part of what we view as Casa's job is It's actually to tell that story in a way that helps people understand why it's important. And I think that it is aided by the fact that our governments and world in general is kind of, falling apart in some areas right now. And so people, that accelerates the process for people to kind of wake up, as you say. And so, we are seeing more people saying, \"I wanna hold my own keys, I understand the- You know, the dangers of not doing that. I think we've saw, I saw a, an article last week maybe, talking about how there was a big spike in Signal downloads, so people who were actually going to protests wanting fully in-encrypted messaging. And so that's, it's definitely accelerated by what's going on in the world right now. But I think we're still at the very beginning of this, and as a community, we really have to think about how we are going to spread- This and tell this story in a way that's accessible to more than just ourselves, because that's how we're going to make some of these, important trends and, and ways to think about life like in a self-sovereign manner where you have real control over your wealth and data. That's how we're gonna help that grow is by, is by really thinking about that from outside of our normal box. So, to answer your question s-succinctly, I think it's being accelerated, but we're still early stage."
    },
    {
      "speaker": "stephan",
      "time": "58:21",
      "start": 3500.63,
      "text": "Yeah, great comments, and, look, I think that's just about all we've got time for. So, Nick and Jameson, thank you very much for joining me. I've really enjoyed chatting with you. Where can my listeners find you guys online? Yep, so check us"
    },
    {
      "speaker": "nick_neuman_jameson_lopp",
      "time": "58:33",
      "start": 3512.91,
      "text": "out at, at Casa Hodel on Twitter. our website is keys.casa and our blog is blog.keys.casa. And of course, personally, you can always follow the inimitable Lopp at lopp on Twitter. My Twitter"
    },
    {
      "speaker": "stephan",
      "time": "58:51",
      "start": 3530.97,
      "text": "is at nneuman. Fantastic. well, I think that's pretty much it, so thank you for joining me, guys. All right, thanks for having us. Alright, get the show notes at stephanlivera.com/slash-one-eight-two for this episode. Also, if you guys have a YouTube account, make sure you subscribe to my YouTube channel, YouTube.com/stephanlivera. I'm gonna try and do some more livestream interviews and the occasional solo stream, so you can catch that there, and I probably won't post the solo streams onto this podcast feed, so make sure you subscribe on my YouTube channel for those. That's it from me. See you guys in the citadels."
    }
  ]
}
