{
  "episodeId": "SLP231",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "and_renowned_hardware_wallet_maker": {
      "name": "and renowned hardware wallet maker",
      "role": "guest",
      "tag": "AND"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.6,
      "text": "Hi, you're listening to Stephan Livera podcast. Today, for episode two hundred and thirty-one, are you thinking about creating a hardware wallet and how would this work if you wanted to do this as part of a multi-signature quorum? Well, Stephan Snigirev is rejoining me. He's the CTO of Crypto Advance and he's a very well-known hardware wallet maker in the space, and we talk about Specter DIY. So we talk about why make your own security model versus other hardware wallets, airgapping with QR codes, how to use this as part of a multi-signature setup, as well as Some updates on Specter Desktop. Also, Stephan has an announcement about the Specter Solutions web store, so listen out for that one. This show brought to you by swanbitcoin dot com, the best place to auto-stash your BTC in the US with incredibly easy setup and low fees. They have recently announced availability in New York, so Swan is available in all fifty US states. They've got a range of new features too, like xPub support by Gigi, so you might wanna get a hardware wallet and use that to automatically withdraw to a new address every time. Swan Service is built around regular stacking, but if you want to wire money in for a special smash buy, support is coming very soon. They're Bitcoin only, they're focused on teaching people to self-custody, so you should send all your new coin of friends there. This is a company focused on helping customers stack Sats safely and easily. Go to swanbitcoin dot com slash new york to sign up. This show also sponsored by CipherSafe, ciphersafe dot io, producing the CipherWheel product. So we're talking about multi-signature and security and backups, well, make sure You have invested in backing up your bip thirty nine seed in a way that is fireproof, waterproof, rustproof, petproof, and tamper evident. The Cipher Wheel is a metal backup product coming in a wheel shape and it masks the words of your seed, and it's also got a padlock tamper evident seal so you know if it's been opened. So make sure you or your loved ones have access to your bitcoins if an accident occurs. Go and order yours at ciphersafe dot io and use the code livera for a discount. Knox is a Bitcoin custodian dedicated to ensuring During their insurance protection covers the full value of their customers' assets. For example, suppose a fiduciary wants to hold two hundred and fifty million dollars of Bitcoin with Knox. Knox will seek to obtain two hundred and fifty million dollars of insurance dedicated exclusively to that account and adjustable to volatility, no fractional coverage or narrow scope insurance for what it's worth at all to transfer risk. If you are a Bitcoin company, investment fund, trust, or family office, check out Knox for your insured custody. That is knoxcustody dot com. Stepan, welcome back to the show."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "02:44",
      "start": 163.59,
      "text": "thank you, thank you Stefan for having me. happy to be here again."
    },
    {
      "speaker": "stephan",
      "time": "02:49",
      "start": 168.66,
      "text": "Yeah. So I see you and Ben and the team, and Moritz at Crypto Advance have been doing an excellent job with Specter Desktop and also Specter DIY. So I'm excited to chat a little bit about this. So can you tell us a little bit about why you went about doing this project?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "03:09",
      "start": 189.07,
      "text": "yeah, so I'm very happy that- That, I actually, here now, it's like a perfect timing because, we just released, made a new release, of Spectre DIY. but yeah, first about, why. basically, I think that more hardware wallets is better and, more different security models is also better. so, originally we started designing Spectre DIY as, one of the multi-signature, cosigners, for your host, for cold storage. and, we also wanted to, make the security model flexible because, normally with hardware wallet, wallet vendors, what you have is what they decide is good for you. and, our idea was to make it more like a, developer tool and, also a tweakable hardware wallet, let's say a first hackable hardware wallet, even though it, sounds terrible. yeah, that's, you can actually- Just according to your security model."
    },
    {
      "speaker": "stephan",
      "time": "04:13",
      "start": 253.43,
      "text": "Yeah, so you mean hacking in a good way, right? Hacking in the, toying around as opposed to, I'm, attacking you and stealing the secret out of this hardware wallet kind of way, right?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "04:23",
      "start": 262.58,
      "text": "yeah, so it's more like, tweaking it according to, how you feel more comfortable. Yeah. Yeah. So"
    },
    {
      "speaker": "stephan",
      "time": "04:30",
      "start": 269.6,
      "text": "can you just give us a bit of a background for listeners who aren't familiar, what is, what is it, what does it look like? What are some of the kind of key points to note about this?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "04:40",
      "start": 280.17,
      "text": "yeah, so, the main idea was that, first we want to avoid supply chain attacks. so we started developing it, from off-the-shelf components. and as a base, we use, this-developer boards by STM Microelectronics. So it is a pretty nice board with, large- The screen and, the microcontroller is pretty capable, but, pretty much similar to, the microcontrollers that run on Trezor, Ledger, and Coldcard basically on all the hardware wallets. and then, because I'm paranoid, I also thought that it would be nice to have, a good air gap and still, convenience. So we decided to add a QR code scanner. and at the moment, what we have is, this discovery board plus the QR code, code scanner, so we can, be completely air-gapped and we have full control of the data flow. So, yeah, QR codes are, are, very, very limited, in, amount of data that it can transfer, but also you have better control. So like either you're scanning or you're scanning back, so you control everything and you can stop if something doesn't look right. and, recently we- We also added, support for, secure elements because, well, better to have an option, to have a secure element, and we do it, with Java cards. so these are basically these, plastic cards that you normally use for your government IDs, for banking, cards and, all of these kinds of things. and, you can actually program it, if you buy one, also of the- yourself, you can program it to do what you want. and we developed, a Java card template for that, as well, such that, you can, even with all this DIY approach, you can still have some hardware security."
    },
    {
      "speaker": "stephan",
      "time": "06:45",
      "start": 404.71,
      "text": "yes. Great. So with the Java card, what's required to make it able to read that? Do you need another part to add to the kit or how does it work?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "06:56",
      "start": 416.34,
      "text": "yes. So, unfortunately, we were not Not able to find, extension boards, on the market that supports this, smart card slot, so we had to design our own, and, this slightly ruins the idea of, only off-the-shelf components, but, as I said, Spectre is made very, flexible, so you don't have to use them. and, yeah, so what we, currently did, we, manufactured a bunch of these, extension boards, and we are, putting them, online on the web shop so people can actually, get them. But again, it's not, critical. I mean, it's nice to have, but it doesn't must to have, right? So, you can, live without it as well."
    },
    {
      "speaker": "stephan",
      "time": "07:51",
      "start": 470.92,
      "text": "I see, yeah. And so just for listeners who might not have seen this before, there are some videos floating around on Twitter and on the internet around how to make this What it looks like, but essentially it's kind of iPhone sized and it's got a screen and it's also got the QR, so that's just so you have a rough idea if you haven't seen roughly what it looks like and stuff. So can you just talk us through what's the process look like if you want to make one?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "08:19",
      "start": 498.77,
      "text": "so in our GitHub repository that I think that we will, link in the description, we have a document, called shopping, where we basically list all the parts that you need to buy. you need to buy this discovery board, and they are available in many electronic shops, like Maestro, DJ King, then, the QR code scanner, it is a little bit, longer to wait because they are coming from China. but they're also not security critical Because, it is basically a dedicated thing, that only, captures images and, transfers this, data, to the main microcontroller. and, in principle, the only, extra thing that you need is, the pins to connect the wires. and these are also like twenty cents or so, in any electronic store. and, for full air gap and, to make it itself, can Contained, you probably want to add a power bank, so the board can be powered from, one of, USB ports, taking a normal five volts from the power bank. So basically three components, that you can put together without any soldering, makes sense to use some duct tape to, connect it all together. but if you have, nice soldering skills, then you can also make it a little bit more fancy, so like the very first early prototype that I made I just put together in a day, prototype board where I had, battery and the QR code scanner, everything wired and connected to these, Arduino, compatible headers, directly. So then it is a little bit more compact, and, easier to use. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "10:08",
      "start": 608.04,
      "text": "Great, and can you give us an idea of the cost involved?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "10:13",
      "start": 612.76,
      "text": "so I think that the discovery board is around, sixty bucks. QR code scanner is, around, forty. power bank, I have no idea. Probably people have, power banks lying around at home, so let's say it's three. so in principle, in one hundred, dollars you can, get the device, fully assembled. then probably you want to add some cost for the, three D printed enclosure or something, and, it's very nice to see that people in the community actually Building these enclosures and, putting them online as well, so you can, either download, files or, or, buy directly from them, and, Yeah, so this is like, one hundred. And if we are talking about, our, developer kits, that's this extension boards, that includes both the battery and the QR code scanner and the, smart card slot. then I think it's around ninety, if I remember correctly. Yeah, something like that. so then it will be a little bit more expensive, but also you will have a, a possibility to, have a secure element."
    },
    {
      "speaker": "stephan",
      "time": "11:31",
      "start": 691.28,
      "text": "great, great. and so,"
    },
    {
      "speaker": "stephan",
      "time": "11:36",
      "start": 695.61,
      "text": "how would you compare this kind of wallet versus some of the other hardware wallets that are out there, some, you know, like Trezor and Ledger and Coldcard and so on?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "11:47",
      "start": 706.95,
      "text": "okay, so, first, we introduced a few, different modes of operation of this hardware wallet, so for example, with Treasure and Ledger and Coldcard, the only way how you use them, is how, they're designed. So Treasure, stores the, secret on the microcontroller, Coldcard stores it on the, secure element, but gets the secret every time when you want to do any cryptography And ledger does, the other way around, that all the cryptography is happening on the secure element and the secret stays there. so, in, our, model, we have, different, options. So first, when you turn on the device and you enter your recovery phrase, it doesn't actually save the recovery phrase. So then it operates in, let's say, amnesic mode. So whenever you turn off the device, it just forgets the secret. And it's pretty hard to hack something that doesn't store the secret. so, if you r-remember your recovery phrase, for example, then you don't really need to, store the secret anywhere, you just retype it every time when you turn on the device. then, the second is more like Trezor, security model, so you can save the secret, on the microcontroller itself, on the, this application microcontroller, but, So this is, how we call it reckless mode, because, yeah, application microcontrollers are pretty easy to hack and, yeah, you know, you probably also saw plenty of, hacks on Trezors, mostly. I mean, Trezor is great, but, this is what you can do with, fully, open source, microcontroller. then, another option that we added recently is- SD card support. So basically, when you insert your SD card into the device, and, you can store your secret encrypted, on the SD card. and then, for example, you can keep your hardware wallet at home and you always take your SD card, with you, and only when you have both of these pieces together, then you have access to secret, because it requires both the, part of the secret encryption secret that is stored on the device And, the SD card that actually, stores your Bitcoin, private key, encrypted. and, so this is more like, something in between, treasure and code card, I would say. hard to really, align them. Yeah. and then with Java cards, we have two outlets now. one, if you don't trust Java cards because they are using proprietary, Java card OS And then our open source applet is built on top of that. then you can use, the model similar to Coldcard, when your secret is stored on this, secure element, but it is also encrypted, it is pin protected, but, yeah, you need, the device to get the secret out and you do all the cryptography, on the main, microcontroller. and then the last one is more like Ledger security model where you can put your secret on the Jalapay and other crypto is also happening there, and then there is no way to get, the secret out of the secure element. So, yeah, trying to cover all possible, Security models and everybody can decide, what fits better for them."
    },
    {
      "speaker": "stephan",
      "time": "15:34",
      "start": 934.32,
      "text": "I see, yeah. And I, I suppose this is one of those points where, depending on how you are using the device, it, like for example, you might do it in a more- Let's say reckless way, but if you're doing it as part of a multi-signature quorum, well, then maybe that makes sense for you, depending on how you're thinking about your security, versus if you were, you know, to try using this maybe for like small amounts as kind of like a more, single-signature small amount kind of warm wallet thing, maybe that would make sense for you."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "16:11",
      "start": 970.84,
      "text": "Yeah, this is actually how I use it. so I have, one of Bitcoin keys. That is saved on the device that I use for, well, not everyday spending, but, spending from time to time, and, then I also have my, recovery phrase, well, that I remember, that I use in the multi-signature setup with, other hardware wallets, and actually Specter Desktop appeared, as a tool for, this cooperation between, well, creating the multi-signature coordination of the multi-signature between wallets. Because, we started designing it as a multi-signature, cosigner, and so we just needed a tool that, will be able to work with other hardware wallets as well. a few other things that's, kind of what we make slightly differently compared from other hardware wallets. yeah, so air-gapped is nothing new now because we have already covered it, it is also using QR codes for, communication. Coldcard is a pioneer of, air-gapped, so they use Use SD cards, and, yeah, ours is also, air-gapped. and, then another thing is, we are using Bitcoin Core's, library, libsecp256k1, and, everybody else, as far as I know, uses something different. So Trezor and Coldcard use Trezor's cryptographic library, and Ledger uses, their, hardware, accelerator That's, elliptic curve, implementation probably. so here we have also, something different on the cryptography side, so that also helps, for this multi-signature because, more your hardware wallets-- well, if your hardware wallets are very, very different, then, the probability of hacking all of them, goes to zero basically."
    },
    {
      "speaker": "stephan",
      "time": "18:10",
      "start": 1090.28,
      "text": "Actually, one other point I wanted to go back to, just with the QR codes, what's your thought on, well, first of all, how much data you can transfer through a QR code, and maybe you just wanna tell us a little bit about the use now of like animated or GIF QR codes as opposed to just the standalone QR codes. Have you found that to be a better experience or more like easy to make it work?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "18:35",
      "start": 1115.48,
      "text": "yeah, so it is, it is really great. So, I, I want- I want to mention that, Christopher Allen is, doing a really great job, with his team, standardizing these, animated QR codes, dynamic QR codes, and, this is really great because then you don't have a limit on the amount of data that you can transfer, so you just, keep scanning a large PSBT without any problems. so, what's, is tricky is when you are using QR codes, then you need to process an image and then you need a pretty large, image processing library somewhere, that, does it for you, and then more code means, larger attack surface. so what we decided to do, instead of using a camera and, displaying the image that you're scanning on the screen, that would be much more convenient from the user pers-perspective, but, we decided to go other way around, so we have a dedicated QR code scanning module that has a separate microcontroller that does all the image processing And then, sends the data that it scans, to the main microcontroller, over a very simple UART serial interface. Now, so then, we kind of decouple this additional attack surface from the main microcontroller that is, controlling the secrets to a dedicated one. So I would say that, it is a reasonable trade-off in terms of security and, also we, use a slightly, more Unified, PSBT transaction format, so like, it is PSBT, but in order to, decrease the amount of data that we are sending back and forth, we actually,"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "20:25",
      "start": 1224.63,
      "text": "Use some proprietary fields that are specified, in, yeah, so in PSBT standard, you, you can use certain proprietary fields, to tell the hardware wallet what wallet to use. So, I mean, you don't need to pass, a lot of data if you know that the hardware wallet knows about the wallet. You don't need derivation paths, for every signer, you don't need xPub's, you don't need witness scripts, you don't need, many, many things. if you assume that the hardware wallet, knows about the wallet, so, our approach here is that, you set up the device and tell the device that, okay, this is the wallet that I want to use. It is, for example, seven of eleven multisig, and, yeah, now whenever I want to sign for this wallet, I just can say, the hardware wallet, okay, use this wallet, and you know how to derive everything for that. And this is just the last two indexes of the deri Information path that you need, otherwise you figure out everything yourself. And, when we tried this, we actually saw that in, ninety percent of cases, everything fits in one pretty small QR code. So that's also nice. So then you have one QR code in one direction and one QR code in another direction."
    },
    {
      "speaker": "stephan",
      "time": "21:44",
      "start": 1303.58,
      "text": "Yeah. Also, I'm curious, around whether you see any, kind of the flip side, the risks around QR codes and whether that could be used to- To, maybe, I don't know the exact term, but maybe some kind of malformed QR or some kind of malware or some kind of maybe sort of, kind of like a SQL injection attack, that kind of thing. Is that sort of thing possible with this approach of using QR codes? yeah, is that possible?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "22:13",
      "start": 1332.66,
      "text": "so, yeah, this is a threat, if you are processing QR codes, on the, security critical microcontroller, and as we separated it in a different one, I think it's less of a threat, but also I mean, I can say the same about, SD cards, so if there is a malformed SD card that is communicating with the main microcontroller, and, prepares malicious, packets pretending that it is, sending the file data, you can also get the same. So I don't think that there is, any communication channel that is perfect in that sense, and, yeah, just to be, tested and better if it is, like really limited and one, unidirectional. Yeah. So SD cards and QR codes, in my opinion, are roughly on the same, yeah, on the same risk area. I see."
    },
    {
      "speaker": "stephan",
      "time": "23:09",
      "start": 1389.0,
      "text": "And just to clarify there, so as an example, let's say it was some kind of malformed, you know, image or malformed SD card, malware kind of thing, in that sort of- Of scenario, could it basically trick the hardware wallet into thinking it's signing, you know, to the same address? Like as an example, I'm sending to address, you know, one, two, three, and like on the hardware wallet device, would it still show that or what, what we're getting at here is essentially it could be malformed in such a way that it shows, you know, four, five, six instead of one, two, three? You get what I'm asking?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "23:48",
      "start": 1428.43,
      "text": "yeah, yeah, I understand. So, I think, There are more chances to trick the hardware wallet not by, using malicious QR code or SD card, but instead just by, exploiting some vulnerabilities in the PSBT transaction parsing or something. so, yeah, if, for example, the hardware wallet doesn't verify the PSBT properly. in principle, there's still a risk that, yeah, you get arbitrary untrusted data from the host or from somewhere. And There could be some overflows, and, maybe that can be escalated an arbitrary code execution, and if you have arbitrary code execution, then, it can do whatever you want, with, whatever it wants, with the, with the microcontroller basically. but, I think that if, we put enough efforts into actually checking this particular piece, so like we, really need to make sure that The data that we are getting from the host should be completely untrusted and verified with, many, many ways, so like, the size, the, well, the data fields, the format, everything, and if you put a lot of effort into this piece, then you are pretty safe. So this is like the, largest, attack surface, yeah, because you're getting some random data from the host. so I mean, in that sense, if you have limited, data flow, it is better. Yeah, I see. It is still a risk, sure."
    },
    {
      "speaker": "stephan",
      "time": "25:33",
      "start": 1532.53,
      "text": "Right, I see. Yeah, and, and look, I think in fairness as well, it's, it's one of those things where you can talk about some kind of more obscure kind of attacks, but ultimately, we shouldn't let that stop us from taking additional, you know, taking steps to improve our security. And if by using this additional device, we can start using multi-signature, well then, you know, you kinda have to take the, you know, take the good with the bad, right? And if it's an overall net improvement, well then I think that's a fair way"
    },
    {
      "speaker": "stephan",
      "time": "26:02",
      "start": 1562.27,
      "text": "point out as well that, when you do these QR scan, PSBTs, it's actually a really excellent experience. Like, when you-- I've tried it with, Specter Desktop and using, like, the Cobo QR back and forth, and it's like really, really cool to see the kind of scan the QR and sign it, and then, basically flip the screen back and now you're showing the QR of the signed PSBT, and then Specter Desktop can now take that That and then now that's ready to, you know, that's another signature. So it's a really cool, experience for the user as well. So that's also something that, listeners can consider there also. so"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "26:46",
      "start": 1605.65,
      "text": "it is al-also very convenient, like, even if you have, for example, Specter, desktop on your mobile, then you can use this QR code scanning, like a simple flip and flip, procedure, and you don't need to connect anything, to the USB, of the, of your phone, so you don't need all this, communication with USB hardware wallet, so it's, also easier to, yeah. Much easier to, to, to, yeah, just to use this kind of, hardware wallet. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "27:22",
      "start": 1641.76,
      "text": "And actually, I'm, now I'm also thinking of, in the older days when people used to use the whole armory offline, which I'm sure you, you probably are familiar with also, Stepan, but I know, There, there were, I've heard of stories where people were trying to use like a laptop with another laptop to try and scan the QR off, like an armory offline sort of style setup. And now, obviously, in November twenty twenty, we're much more advanced with that, and now we've actually got devices that can do that for us, so that's actually very handy also."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "27:53",
      "start": 1673.15,
      "text": "Yeah, but you still can do, laptops. I mean, if you don't trust hardware wallets, you can actually use a air-gapped laptop, and we tried it recently, with Spect So, you can have, a Spectre desktop with Bitcoin Core running on the air gap machine and used as a signer and another laptop that is connected to the internet used as a, coordinator. The online,"
    },
    {
      "speaker": "stephan",
      "time": "28:17",
      "start": 1696.67,
      "text": "yeah."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "28:17",
      "start": 1697.37,
      "text": "Yeah, and, well, it sounds, it looks ridiculous when you try to scan, QR code on one laptop using another laptop, so it's like, this laptop sandwich. but, it works, yeah. So, and I think that there might be people that- find it's, more useful and more, confident to use this kind of setup."
    },
    {
      "speaker": "stephan",
      "time": "28:39",
      "start": 1719.14,
      "text": "Back to the show in a moment after a word for the sponsors. Lend at HodlHodl is a global non-custodial Bitcoin-backed lending platform that allows you to lend and borrow anonymously on your own terms. HodlHodl offers a P2P lending solution, ensuring a secure and transparent collateral storage system by providing unique multi-sig escrow for each deal. This is a way to grow your savings and earn. Attractive returns on your investment. So if you have any stablecoins lying around, create your offers and earn interest by lending on Lend at HodlHodl, or if you are a Bitcoiner and need some liquidity, you can borrow stablecoins and keep hodling. With HodlHodl's Lend platform, you set your own terms and put up offers depending on how long you want to borrow or lend and interest rates. Go and check it out at lend.hodlhdle.com. And lastly, Unchained Capital is building Bitcoin-native financial services on a foundation of multi-sign Multisig vaults are designed for ultra secure long term storage and have no setup or storage fees if you build them on your own. If you want the white glove treatment, their team will teach you all about multisig, ship you two hardware wallets, answer all of your questions, and then deposit a thousand dollars of Bitcoin in your vault through their concierge service. You can buy Bitcoin through their OTC desk for purchases fifty thousand dollars or higher straight into your new vault, which is great for Bitcoin self-directed retirement accounts and for companies moving Bitcoin to treasury. Their advanced business accounts, OTC desk, and concierge service can also help move your corporate treasury to Bitcoin where your team controls the private keys. Check them out and enter code Livera when ordering a concierge orderboarding service to get fifty dollars off. Check out Unchained Dash Capital dot com for more. One other point actually, just on QRs, I've noticed in some cases it can be difficult if you've got a bad webcam, for example. Like sometimes, de-depending on what laptop or computer you're using, sometimes it's like hard to do the QR stuff if, like, the webcam on, it's like a old, you know, crappy laptop, sometimes the webcam is a bit difficult. Have you seen that kind of thing, or is it more like in your experience it's actually worked pretty consistently?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "30:45",
      "start": 1844.82,
      "text": "so, yeah, especially if you have a very Webcam and you are, for example, it's, late in the evening, so your lights are dim, in the room, then you might have problems scanning the QR codes, so it can be solved, so we have this, feature similar to what Cobra has, like you swipe or click on the QR code and it goes, Fullscreen with a white background, then the webcam, handles it easier, but still sometimes there are problems, yeah. So we are trying to solve it so, you need to reduce the QR code, frame size, for example, and then like, have more sequential QR codes to get it, scanning more reliably. I don't really know what you can do with it. We all, the only thing that we can do, we can use a laptop with a very bad webcam, ourselves and, try to find a way to make it working, yeah. So I'm lucky in that sense, I have a very crappy webcam. Yeah, hah"
    },
    {
      "speaker": "stephan",
      "time": "31:54",
      "start": 1913.95,
      "text": "Or is going, the extra mile. and I think the other big point of this, like the whole point, one of the points of this, Specter DIY device is the i-- the idea of trying to remove supply chain risks. So how much supply chain risk do you see with, let's say, the other hardware wallets, and potentially this is something that, okay, so let's say over the next year or two there's a big bull market and, you know, it kind of goes crazy and it's hard to, you know, we start seeing Those resellers of the fake treasures or whatever, I guess that's the kind of risk that we could see in terms of supply chain, we might see more and more people try to do that kind of fake hardware wallet attack, right?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "32:38",
      "start": 1957.68,
      "text": "yeah, I think that, there were already a few attacks like that, so I do remember that, there were, like, there was a shop of, like, a reseller of the ledger, on Amazon, that was, shipping the device with already- Pre-initialized recovery phrase, so the guy just wrote down the recovery phrase on the recovery sheet and was shipping it with the recovery sheet that he obviously knows, so this kind of things. I think with Trezor it might, happen as well at some point, but, at the moment this, attacks are very simple and if you just keep a few simple rules like only order the device from, directly from the vendor, so from the webshop of Treasure Ledger, Coldcard and so on, then it's much harder to perform this kind of attack. There is still a possibility that, some DHL delivery guy, will take your device and, open it and do something with it or replace it. but I think that at the moment we are not at this stage, but I am expecting that something like that may happen in the future. Yeah. So, there is a risk, but, everybody should be careful, yeah."
    },
    {
      "speaker": "stephan",
      "time": "33:56",
      "start": 2035.99,
      "text": "Yeah, and, and as-- and to be fair, it's not just that risk as well of coming from the hardware wallet, but it-- to the customer, but it could also be an upstream supply risk, so it could be unknown to that actual hardware wallet manufacturer."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "34:11",
      "start": 2051.45,
      "text": "so yeah, if, the, hardware wallet is manufactured somewhere like outsourced, then this, factory workers can also, do something with the chips and it is also a little bit scary. But as far as I know, Ledger and, Trezor are manufacturing, all the wallets, in-house, so like in Czech Republic and in France, so they kinda have a better control of the, manufacturing process. And so in- That's good that they're taking this step, yeah."
    },
    {
      "speaker": "stephan",
      "time": "34:43",
      "start": 2083.15,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "34:46",
      "start": 2086.25,
      "text": "alright. And so in terms of, I guess the downsides of, this wallet, I guess you would say it's, it's, you know, it's relatively new, it's, you know, it, it still kind of needs a bit of time to be battle tested, but, do you have any other views to share on that?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "35:04",
      "start": 2103.62,
      "text": "yeah, so that's, that's definitely true. So the project is, pretty immature. so the team is pretty small, so at the moment, I'm working on all the high-level logic, of, Spectre DIY and Mike, our security guy, is doing more low-level stuff, so like the secure bootloader is his work and, things like that. So basically, the problem is that, yeah, we have a very small team, not enough code reviews, no really like, certifications or whatever, so this is very, very well- Welcome, and also regarding the Java card template, for example, would be nice to review that because this, is the thing that is storing the secrets. So, but we also have this disclaimer in, the repository that it is work in progress. so, I still think that, Specter can be used, either for small amounts, or as a signer in the multi-sig setup, because, yeah, I mean, I hope I, I believe it, it will happen for sure that the project will become more mature, and we'll also be able to, confidently say that, okay, this is now a secure hardware wallet that you can use for your main funds. But, I mean, multi-sig is always better. It's, it adds a little bit, of complexity of the backup, but otherwise, yes, I was saying in all my talks, everything can be hacked, including our hardware wallet. So, yeah. Yeah. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "36:43",
      "start": 2203.33,
      "text": "Yeah. So, if we were to talk about using it as part of a multisig, so obviously you can use it as part of, with, alongside Specter Desktop, which is, a great multisig coordinator app, Can you tell us a little bit about, what that looks like if you want to use it as part of a multi-sig quorum?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "37:04",
      "start": 2223.78,
      "text": "so basically the setup is very similar to any other hardware wallet. So first you need to get your, master public keys, into Specter Desktop or any other coordinator. and, yeah, this is just scanning QR codes. and, after that, you can create the multi-signature wallet. and you need to import this wallet into the device. As I mentioned before, we are, using this, assumption, we are assuming that the hardware wallet knows about the multisig wallet, and also it helps the hardware wallet to verify, the transaction. So, if it knows about the wallet, then it can, say that, okay, this is actually change, and this change goes back to exactly the same wallet. Or, for example, you have two outputs, and one goes to one wallet That I know, and another one goes to another wallet that I know. so for that, in Specter Desktop, you just need to, get the QR code with the descriptor of the wallet, and Specter DIY, just scans this descriptor and can calculate the addresses and all other information from that. So, yeah, we are, using, Bitcoin Core descriptors, as the definition of the wallet."
    },
    {
      "speaker": "stephan",
      "time": "38:23",
      "start": 2302.96,
      "text": "Right, and that's a more advanced feature also as, I don't, I don't think many other wallets are using, output descriptors natively. So that's a cool, point to note there. So, I, I guess in practice, that's actually two descriptors, right? Because one would be, I forgot which one's which, but one's the internal chain and the external chain, one's the change chain, right? So I guess you would have both descriptors, right?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "38:47",
      "start": 2326.64,
      "text": "yeah. So, we simplified it a bit such that, receiving descriptor, and then if it is, slash zero slash star, then we can assume that the change descriptor is basically the same, just the derivation path, i-is, using, slash one slash, slash star. So basically, you can scan one descriptor and get a default, receiving and, change branches there. I think that it would be nice to have like more general descriptors so that you can... Fine, okay. This is the receiving and this completely different thing, is the change, but, we didn't implement it yet, so would be nice to have actually. Yeah, but we also don't see the demand really, because, everybody is using currently the default, multisig and default descriptors. so we can, leave it like this for now."
    },
    {
      "speaker": "stephan",
      "time": "39:44",
      "start": 2384.23,
      "text": "Yeah, I see."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "39:45",
      "start": 2384.77,
      "text": "Yeah."
    },
    {
      "speaker": "stephan",
      "time": "39:46",
      "start": 2385.53,
      "text": "and, also, I'm curious about whether you would be interested to do this kind of feature or whether that already exists. Is this idea of, so for example, let's say you wanna use Michael Sacksman's, you know, guide and you wanna do a seed picker, and that guide currently Need to basically, you would pick out twenty-three words, and then the, the twenty-fourth word is a checksum. So is that something that you might be able to kind of internally calculate inside the wallet or on the device?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "40:15",
      "start": 2414.59,
      "text": "so we actually, integrated this, feature recently, so two, features on the, entropy side. the first one is, you can use like meat-generated entropy. so you just throw the dices and, pick the words at random or like you use a hat with, This, all the words cut it until you select, twelve, eighteen, or twenty-four words, and, Inspector DIY, you start entering these words, and then when you hit, to the, twelfth word, and enter the last twelfth word, it will suggest you to fix this word if it detects that the, checksum is incorrect. So basically, you can generate the recovery phrase fully offline, and, with Using only physical entropy and then, fix the last word similar to what, SeedPicker does. So the only difference is that SeedPicker is, adding the twenty-fourth word, and we instead are fixing the twenty-fourth word. so, fixing makes it, the, the whole process a little bit more deterministic. So instead of, filling some bits with zeros, we actually use all the entropy of the user but, replace the checksum with the correct one. and then- Another, interesting feature that we added recently, if you aren't, sure about how good is the, true random number generator that is on the device, then when you are generating the recovery phrase, it first, shows you the recovery phrase that you can use, just like that, or you can click on every of the word, see the corresponding like eleven bit string, and then flip the bits. So basically you can You can, take, for example, eleven coins, shuffle them and, yeah, throw them and see which of the, coins are heads and tails, and then on the corresponding word, you just flip the corresponding bits. So then you're basically XORing, the entropy, mixing together the entropy that was generated by the hardware with your own physical entropy, and, it is fully verifiable, it doesn't change, any other word, except the last one to me Maintain the correct checksum, and then you can improve your, randomness even further because if you XOR into, random numbers, the result is, Better than any of the incoming randomness, random things. Yeah, I see. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "42:51",
      "start": 2571.28,
      "text": "So that's the, again, again, so this is one of those points where I don't understand it fully myself, but there's this, function called XOR, and so that basically mixes the randomness together, and that's kind of a function that helps you get additional randomness. But I, I wouldn't be able to explain any of the detail around exactly how it's doing that."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "43:10",
      "start": 2589.93,
      "text": "yeah, sorry, and sorry for going a little bit into, technical details. but I think that it is also like another level of paranoia. So like if you are, very paranoid, then you probably want to figure out how this feature works and, use it as well. Yeah. So you can use that."
    },
    {
      "speaker": "stephan",
      "time": "43:28",
      "start": 2608.44,
      "text": "Gotcha. Yeah. And, so in terms of future plans, is-- what can you share with us there? I know, so recently you were to-- you were chatting a little bit about, the use of a, a secure, microcontroller."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "43:44",
      "start": 2624.41,
      "text": "so, yeah, the interesting thing that, I, figured out, in, Embedded, conference last year, that now there is actually a microcontroller, that doesn't require-- that is secure and doesn't require NDA. so Maxim Integrated, the company, American company, decided to make this experiment. they developed a chip that doesn't require NDA, but it has, certain- Features, like voltage and clock monitors, that, provide you some hardware security. so it isn't like the high-grade secure element because, well, that kind of microcontrollers normally go through certification and then they require NDA, because, To get higher points in the certification, if your thing is closed source, you get extra points. and this one is slightly different, but still, it's, the unique thing is that it doesn't require NDA and it has some hardware security. so we were thinking about using that and, designing, basically the, the board that will look exactly the same, as the, Java Card that includes that microcontroller inside and that can't be a Drop-in replacement for our current Java Card implementation. So we will still, maintain the Java Card parts and, also make, this fully open-source, version, that's, You can control better and we can control better, so that's, very nice, yeah, and looking forward to this."
    },
    {
      "speaker": "stephan",
      "time": "45:25",
      "start": 2725.42,
      "text": "Yeah. Aa-- out of curiosity, do you know roughly how much that piece of equipment costs?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "45:32",
      "start": 2731.97,
      "text": "the microcontroller costs like twenty bucks, maybe ten bucks, I don't know, they are really cheap. All the microcontrollers are very cheap, even the secure element that is like high-grade and NDA graded and so, and certified, they cost, nothing really."
    },
    {
      "speaker": "stephan",
      "time": "45:47",
      "start": 2746.59,
      "text": "Yeah. Okay. Cool. and, yeah, anything else you can share with us in terms of, future plans and what you're doing with Specter DIY?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "45:55",
      "start": 2755.3,
      "text": "yeah. So one important thing is, we start, the limited edition of, li-limited sale of our, developer kit, our Specter Shield. this is what I mentioned that includes the QR code scanner, smart cards, and, also we are, cooperating with CryptoCogs to make the, Nice 3D printed casing for the board, and, I think that we will put the shop online, when this, podcast is out, so basically, there you can buy either the fully assembled thing together with the discovery boards, and, the smart cards, or you can only get the, this extension board, and all the, the rest of the parts that are like security critical from, from random suppliers. and, It will be like orange pioneer edition, fifty pieces, because we want to get some feedback, initial feedback from the users to see, what we can improve and how we can get it, make it better, because, at the moment, yeah, there are a few people that, actually assembled, the DAI themselves and are using them, and we get some feedback from that, but, currently there is no easy way to get the smart card secure element support for it. So that's why we are starting that. then, otherwise on the future plans, let's see how it goes with, yeah, with the response of the community and, maybe we can, do something like a fully manufactured, version of Specter DIY. So one thing to note here that we will always maintain the DIY, kind of spirit of the project. So, DIY first. And then, all this, stuff that we sell is more like for convenience, for lazy people or for, not very sophisticated people, right? or"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "48:01",
      "start": 2881.31,
      "text": "I mean, it would be really, really nice to have, like, more, feedback, but also more contributions because, yeah, you can do many things with these hardware wallets, and, like really looking forward to things like, Miniscript, maybe Lightning and Coinjoin, and, Liquid Network, all these kind of things are really, really exciting. so let's see how it goes. Schnorr coming soon, that will be Huge. yeah. then, other, other than that, Specter, like the whole project, we tried to make it, platform independent. So in principle, you don't have to use this discovery board and, everything, all the hardware that we selected, but actually it can be ported to anything else. So if you want to make a version that is, with Bluetooth and using ESP32 or M5Stack or something Like that. in principle, it is possible to port it there. So, I think it would be very nice to have, like, maybe some documentation and a guide how exactly to port it, because then, you spread the risk, of the supply chain even further, because now people don't know what exactly you will buy for the Spectre DIY. and, another interesting platform to look at is actually RISC-V microcontrollers that are, Timing, there are a few that are very powerful already, and Risk Five, as it is a new architecture, it also has some extra security features and also don't have, legacy, lying around and, potentially introducing some random, Backdoors, in your microcontroller. So that's, also nice. and in general, yeah, sorry, just too many points, too many points."
    },
    {
      "speaker": "stephan",
      "time": "50:02",
      "start": 3001.7,
      "text": "Actually, just on the risk point, risk five, so my understanding with that, it stands for, I think, reduced instruction set, computing or something like that, but essentially, it's like this whole push towards open hardware, right? So I guess the idea is we want not just open software, but we want open hardware. And this is part of the push in that direction also, right?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "50:24",
      "start": 3023.94,
      "text": "Risk Five, i-it is a little bit tricky, yeah. So it is a standardized instruction set, and then the idea is that any, any, silicon vendor can implement the microcontroller that implements the set without the need to pay, royalty fees. how open they are is a different question because normally the microcontrollers, are not just the core and the instruction set. We also put a lot of other components there, and, most of the companies that are manufacturing RISC-V chips now, they still put proprietary stuff around it. but the nice thing is that you can actually take this instruction set and you put it, for example, on the FPGA, and, it is like a more open and controllable platform where you basically define how transistors are wired together, and then have, your own, RISC-V microcontroller Based on that, it will be a little bit more expensive, but it is way more open, so less probabilities of, backdoors, by the manufacturer or implementer. And I think one very important project in this space is, Precursor by Bunny. so this is the, risk five based, communication device. Basically, that would be a replacement for your phone for encrypted calls and, things like that. Like that, and also like, for storing the keys. And he's using exactly that, so FPJ's and Risk Five, implementation there. and, yeah, you can also just get rid of the wireless mo- wireless, module there, and then you get, very interesting hardware wallets from it."
    },
    {
      "speaker": "stephan",
      "time": "52:08",
      "start": 3127.92,
      "text": "Very cool. Yeah, thanks for clarifying that. Yeah, it's, interesting to see what's happening with that stuff as well. I'm definitely excited to, get a Specter DIY for myself, so I'll definitely be, hitting up that web store when it's available. also wanted to just chat while we've got you here, also to chat a little bit about Specter Desktop updates. You guys have recently put out a new version and you've got some, you know, new features coming and things like that, so, can"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "52:38",
      "start": 3157.7,
      "text": "yeah, so from the last time when we were on your podcast with Ben, many things happened. So we, released the app that is actually a standalone app, we got the, Tor support that is kinda working and, improving that, currently. we got replaced by fee, that is very important feature for, high fees or crazy, crazy random fees that we currently have, in Bitcoin. then, in general, the app became much more stable, and this is, mostly, due to, Ben and Kim. So Kim, is, not so loud contributor to, Specter Desktop, that is doing all the infrastructure, continuous integration, testing and stuff. So, thanks to that, and to his work, we became much more stable, and, now we are really, aiming to get to version one so we still need to fix a few things, but, other than that, I think in, a month maybe we'll get to version one that we can say that, okay, Specter Desktop is now, stable and usable and, yeah, go for it, we can recommend it for sure. Yeah. I, I mean, I can recommend it even now, but, I mean, I know that there are bugs from time to time. and it was super exciting to see, how people actually how How many people, are actually using Specter Desktop and, all this, community support and shout outs, it's just crazy. So we just, the whole team is so happy now."
    },
    {
      "speaker": "stephan",
      "time": "54:19",
      "start": 3258.76,
      "text": "Yeah, that's great. I think it's, yeah, you've had a really good, community response. I think, a lot of people were looking for something like this. I, I was also curious, the recent version it mentions an offline mode. Can you tell us a little bit about how that works?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "54:36",
      "start": 3275.65,
      "text": "yeah, so this, I mentioned it, a little bit earlier about this air-gapped laptop. So the offline mode, is that, if you have an old laptop and WiFi doesn't work or you can turn it off, for example, or you buy cheap, laptops where you can get rid of the WiFi, then you can put there basically a couple of binaries, Bitcoin Core and Specter Desktop. and then you can, use it, as a signer. So Bitcoin Core will be signing the transactions, Specter Desktop will take care of the user interface and, scanning out the QR codes and displaying the QR codes. and, then, yeah, your old laptop can become a pretty good, air-gapped machine that, is used as, one more signer. so you probably know about, this Glacier protocol or something like that. And yeah, so I think that they, recommends, using Ergo laptops as signers, but the user flow, user interface, and, and all the, complexity of the setup is, a little bit, Too much for me, I would say. Yeah. Yeah, yeah. and so we tried to implement, this in a little bit more user friendly way, and, yeah, we tested recently and it works and, it works, really great. So on this air-gapped, laptop, you can verify the change, you can, see the outputs, the addresses and everything, and you still use, signing, functionality of Bitcoin Core. so, yeah, if you trust Bitcoin Core, then this Is probably a pretty good, candidate for one of the signers."
    },
    {
      "speaker": "stephan",
      "time": "56:23",
      "start": 3382.89,
      "text": "Yeah. Also, sorry, I, I might have, you might have mentioned this, but I, I think I missed it. So does the Specter offline mode, does that actually have private keys or how, how are you, how are you managing that, in terms of the private key part of it for the offline one?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "56:38",
      "start": 3398.14,
      "text": "so yeah, on the offline mode, what you create, you create a, a hot Bitcoin Core wallet, even though it is not hot if it is offline. but, yeah, then you enter your, recovery phrase there, and then this recovery phrase is converted to, private keys and loaded into Bitcoin Core. so if you want to keep it fully stateless, then you probably need to clean up Bitcoin Core after that, so just delete the wallet files that, Specter created. otherwise, it stores, private keys, in, Bitcoin Core wallet, but I think that you also can, encrypt it, so Bitcoin Core wallet functionality supports encryption with a long password. or I think if you use something like a stateless, OS, like Tails, for example, it will clean everything up for you, automatically."
    },
    {
      "speaker": "stephan",
      "time": "57:38",
      "start": 3457.76,
      "text": "Yeah. great. And also with the Tor support, is that, that's for, is that Windows and Mac? And essentially, you- What would you use that to-- Would you use that to try and automatically connect back to your, let's say, you've got a Bitcoin Core node running at home, is that the idea or what would you, how would you use that? Yeah,"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "58:00",
      "start": 3480.07,
      "text": "so this is the idea that you have a node in the box, either, my node, so Raspberry or your own home brewing or Umbro, and, if it has, Specter or if it exposes, Bitcoin RPC over Tor, then you can- Connect to it, from your laptop, so basically in this case what you need, you can have, this remote specter that is running on your node, that is managing all the wallets and watching all the addresses and prepares the transaction, and then you have the app, on your laptop, that is, providing the access to the hardware wallets, for, this remote specter. So this is, one of the models so you can, avoid running Bitcoin Bitcoin Core on your laptop and still use, Specter for signing, with your hardware wallets while you are, somewhere on a trip or not at home. and, alternatively, if you don't run remote Specter, just Specter on the node, and you just expose Bitcoin RPC over Tor, then you can, also connect to Bitcoin RPC from, your laptop and, also basically do the same."
    },
    {
      "speaker": "stephan",
      "time": "59:17",
      "start": 3556.84,
      "text": "I see, yeah. And that might be obviously handy if you have, you know, multisig and you've got keys in different locations and you've got the laptop and you need to go around to, you know, get signatures and, et cetera, to build the transaction and blah, blah, blah. yeah, I think so. Yeah, one other one, would you consider bundling Bitcoin Core straight into Specter Desktop just to make it like a one, you know, one double-click install for, like newbie Bitcoiners?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "59:45",
      "start": 3584.64,
      "text": "I think it would be interesting, as an option, because, well, I mean, people use, Specter in very different scenarios. So we could have like a toggle, in the settings that either I want to use a built-in Bitcoin Core node and then you configure it, either you want to use it pruned or, or whatever, or you connect to existing Bitcoin Core node. so I don't think that it will happen, until version one at least. So, it is an interesting feature, but it isn't, on the roadmap right now. But, we keep in mind, keep in mind that, yeah, that might be easier. And I also feel like, people that are using Specter Desktop and trying to do like this multi-sign and, things, they probably want to be sure that Bitcoin Core that they downloaded is actually coming from Bitcoin Core dot org. So, I see. Yeah. Yeah, maybe, but, a little bit later."
    },
    {
      "speaker": "stephan",
      "time": "01:00:44",
      "start": 3644.74,
      "text": "Yeah, sure, sure. That totally makes sense to me. also wanted to just chat about pruning while we're here as well. So, right now, if you wanna download the Bitcoin blockchain, I mean, as of, you know, November 2020, we're talking about three hundred and fifty gigabytes of download, or otherwise, if you wanna prune it, I think you can do, let's say, five or ten gigs worth. can you just"
    },
    {
      "speaker": "stephan",
      "time": "01:01:08",
      "start": 3668.62,
      "text": "Inspector Desktop in pruned mode, versus, you know, doing the full download, and then what's the-- I guess what I'm asking is, what's the impact in terms of wallet scanning and wallet use if we're on a pruned version?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:01:25",
      "start": 3685.31,
      "text": "so yeah, the pruned node, it will still download all, three hundred gigs, of, blockchain data and verify that, but while it is downloading it, it will also erase all blocks. So So it will maintain your, hard drive usage to like ten gigs or so. and, this means that you can't easily re-scan, if you are, creating or importing the old wallet that already has a transaction history. so what we currently implement is, you can, re-scan the UTXO set, so you can find all your unspent transactions. but then in order to import them Into the, Bitcoin Core, you also need, proofs that, this, transaction is actually included in a certain block, and at the moment with the pruned node it is not possible. so we have, a privacy concerning workaround, that you can use a block explorer, for example, Blockstream, info, to get these proofs. and then, you can import this into your Bitcoin Core. The idea here Is that, yeah, you kinda tell, potentially, chain analysis companies, what transactions you are interested in, but then at least you, can use the wallet. So, with the, we- May add, we will add, an alternative to that, such that after rescanning the UTXO set, when we know that, we need this and this and this block, we can just connect to, our peers, on the Bitcoin network and download these blocks directly and then parse them and get the proofs, proofs ourselves. but it is, still, in process. Yeah. So, at the moment the trade-off is that, right now you- Need to communicate with, Block Explorer if you want to get your, unspent, but, and you can't get, full transaction history."
    },
    {
      "speaker": "stephan",
      "time": "01:03:35",
      "start": 3815.95,
      "text": "Yeah. I see. so currently, if you, let's say you prune it, you run, you run it pruned, and then you wanna start a new wallet on the Specter Desktop. Let's say, you know, I got a new, Specter DIY, and it was already pruned, right? So I didn't- Set it up before the pruning, then does the app as currently, you know, configured or co-app as currently coded, does it automatically do that fetching from Blockstream dot info or how does that work?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:04:07",
      "start": 3847.13,
      "text": "It, it doesn't do, any fetching, automatically, so you control it always from the user interface. so if you're creating a new wallet, then it will not even try to re-scan, so, it is assuming that it is a fresh new wallet that doesn't have any funds and you can use it as normal. and, if you are actually triggering the scan, then you have a checkbox, either you want to, connect to a block explorer to, to get this data or not. and if you don't, then, well, probably you'll get only a fraction of UTXOs that are in the blocks that are not pruned yet. yeah, so this is the, problematic part. An alternative i-is that when you start, your pruned node You also create the wallets inspector desktop, and then, if they are wallets during this, full scan of the blockchain, it will also, get all the transactions from there. So this is an alternative for old wallets, but for the new wallet, you don't really need, a full node, so you can easily use it with a pront and without any privacy concerns."
    },
    {
      "speaker": "stephan",
      "time": "01:05:17",
      "start": 3917.01,
      "text": "Great. also, you might have touched on this earlier, but I'm wondering whether that's also a future idea whether you would look at that kind of thing of You know, some, for example, Umbrel uses like a Neutrino style and then transitions over to the full node. Is that something you would look at with Specter of using, you know, compact block filters and things like that to try and, give people the, is the ability to more quickly start up? Is that something that you could do, or is that kind of more like, not an immediate,"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:05:44",
      "start": 3944.85,
      "text": "I think it is a very interesting, thing, and, one feature that is missing in Bitcoin Core at the moment,"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:05:54",
      "start": 3954.72,
      "text": "Able to use, this, block filters, while using a prune node, because, okay, the prune node during the sync is downloading all the blocks, so it could potentially calculate, all the, all this nutrient filters, and then you can use that to recover your full transaction history, at least find, the blocks that you care about. so we can, do something like that, like to build, a custom block filter view Either, inspector desktop that is, checking out your proof note and for every box calculates these, nutrient filters that would work, or we can connect to, the nodes that provide these block filters. the problem here is, that there aren't too many nodes that, announce this feature, so, you have a limited set of nodes that can give you these, nutrient filters. and also you can't really verify this filter Users, unless you don't order blocks, so they can lie, about that. But on the other hand, there's no real reason for, lying you about that, because, well, what is the benefit? So in principle, we can connect to these nodes and get all the block filters for, all the blocks, and then from this information we can get the information what blocks we need for the transaction history, and then get these blocks, and then And get the transaction history. it's a little bit, complicated, but it is definitely a very interesting thing to try out, and I was thinking about that in the background for the last month or so, and hopefully I will find some time and, prototype something, that would work with new network filters."
    },
    {
      "speaker": "stephan",
      "time": "01:07:43",
      "start": 4063.55,
      "text": "That's awesome. Yeah, and I just wanna say I really, I'm a big fan of Specter Desktop. I think it's a great, piece of software. I really like using it, and I've definitely-- I can see why it's been so popular amongst the, Bitcoin, community, at least amongst my listeners and the people I'm chatting with, definitely very, useful piece of software that actually makes multisig actually, you know, quite a good experience for, the user there. So definitely, really appreciate"
    },
    {
      "speaker": "stephan",
      "time": "01:08:15",
      "start": 4095.23,
      "text": "and I suppose, might be a good point to wrap up here. So, do you wanna just, you know, tell the listeners why should they be looking at Specter DIY? Why should they go and get one? And, where can they get one if they're interested to get that?"
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:08:29",
      "start": 4109.36,
      "text": "First, before I go to, to the DIY wrap up, I want to shout out to the team, to, Ben, Kim, Morris, and, Mike, who are doing, amazing They're pushing forward, our project, so I'm very happy to have them in the team, and, yeah, I love you guys. and regarding the DIY, first of all, it's a lot of fun and it is a very, interesting piece of hardware that you should definitely check out. and second, it is, very different from, the security models of other hardware wallets, so why not to include it in the multisig if you, if you have the capabilities? yeah, so, feedback is, very, very, very welcome. and we will keep improving, both Specter Desktop and Specter DIY in the upcoming months. and- to get it, it should be, I think, shop dot specter dot solutions, and yeah, you can just check the checkbox there and, get our, extension shield or, check out the shoppings, shopping document in the repository and just get everything yourself and assemble it. it is, very usable without anything from us, and I think this is also a great, thing."
    },
    {
      "speaker": "stephan",
      "time": "01:09:57",
      "start": 4197.71,
      "text": "Fantastic. So listeners, you can find the links, they will be in the show notes, stephanlivera dot com slash two three one for this episode. Stephan, thank you very much for joining me today."
    },
    {
      "speaker": "and_renowned_hardware_wallet_maker",
      "time": "01:10:08",
      "start": 4208.08,
      "text": "Thank you very much for having me. I'm really enjoying talking to you every time."
    }
  ]
}
