{
  "episodeId": "SLP238",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "zach_herbert_ken_carpenter": {
      "name": "Zach Herbert & Ken Carpenter",
      "role": "guest",
      "tag": "ZACH"
    },
    "guest_2": {
      "name": "Guest 2",
      "role": "guest",
      "tag": "GUEST"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:10",
      "start": 9.84,
      "text": "Hi and welcome to the Stephan Livera podcast. Today for episode two hundred and thirty-eight, the market for high quality hardware wallets is heating up and is becoming more competitive with new entrants over time. Today, Zach Herbert and Ken Carpenter of Foundation Devices join me, and we're talking about their new device, which is fully air-gapped and PSBT supporting wallet. This show brought to you by Swan Bitcoin. Bitcoin has emerged as a major player on the global stage. It has been significantly de-risked over the past year with major investors, institutions. Institutions and companies making big investments. At this point, everyone should probably own at least a little. A common way people get started is establishing their initial position with a one time buy and then start dollar cost averaging with automatic recurring buys. Swan Bitcoin was built to do just this. With Swan, you can create a recurring purchase plan like a hundred dollars a week or twenty dollars a day and you can make one time buys. Swan supports bank wires for larger amounts and ACH transfers for smaller one time buys is rolling out to members now. Swan is a available in all states and territories of the US, now including New York, Swan is the best place to send your family and friends when they're ready to get started investing in Bitcoin. Send them to swanbitcoin dot com slash livera and Swan will drop ten dollars of free Bitcoin into their account when they become a member. That's swanbitcoin dot com slash livera. Knox is a Bitcoin custodian dedicated to ensuring comprehensive insurance coverage for client assets. Much of what passes as insurance today isn't purchased for the sake of protection, but For pure marketing reasons, Knox believes insurance should exist to make fund recovery possible, no sharing coverage between customers. Knox takes a unique approach when it comes to purchasing insurance for customer assets. Coverage is set aside exclusively for every customer in a one to one capacity, all with a comprehensive policy covering a range of loss and theft events, including internal collusion. So if you are a Bitcoin company, RIA, fund, trust, or family office, make sure to contact Knox to discuss Bitcoin custody. And insurance. KnoxCustody dot com, CypherSafe dot io producing metal backup seed products like the CypherWell. They have a new product called the Bitcoin Recovery Tag, specifically helping you with recovery. It's an extra stainless steel tag with info like the original wallet, gap limit, derivation types, scripts used, and each of the major hardware wallets all have their own type of recovery tag that you can buy and you can attach this to your seed word backup with the stainless steel cable included. And it even includes a website link for recovery to help you or your heirs recovering the coins on Electrum, so it really adds that value of helping you recover in practice. So Bitcoin Recovery Tag works with any seed word backup device, obviously including CipherWeal, but others such as CryptoSteel or CryptoKeys, Billfold, CryptoTag, Blockplate, and others. So go to ciphersafe.io and use the code Livera for a discount."
    },
    {
      "speaker": "stephan",
      "time": "03:09",
      "start": 189.0,
      "text": "Zach and Ken, welcome to the show. Thanks for having us. Yeah, thanks. Good to be here. So guys, great to chat with you, and I have had a chance to look at your device that you've given me as a tester, but obviously just for the listeners who may not know you, can you just give us a little bit of background on yourselves, where you came from, and what you were working on, before all this Bitcoin stuff?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "03:33",
      "start": 213.0,
      "text": "Yeah, definitely. I can go ahead and get us started. so I have- I've been following Bitcoin since around twenty thirteen, and I've been, you know, I lurked for a few years on, on Bitcoin Twitter and Reddit, and then did a few smaller projects, around twenty sixteen, like for example, I was selling hardware wallets on, OpenBazaar, if you remember that decentralized marketplace. Yeah, yeah. Yeah. So that was, that was a fun and interesting experience. and then I, I have a mechanical engineering background, and I, dropped out of business school actually to join up with a local company, Cryptocurrency space in Boston. So I, I kind of went through the phase of getting really into Bitcoin for the, you know, ideals of decentralization and then getting into some of the other cryptocurrency stuff and then realizing that Bitcoin is what's actually important. so I and, and Ken also, worked for a company, called Nebulous in Boston that was making a couple different products and one of them was Obelisk, and we were making Bitcoin mining or sorry, cryptocurrency mining ASICs for SiaCoin and for DCRD. And so between twenty seventeen and twenty nineteen, we actually learned how to make hardware, and we crowdfunded and, sold and shipped over twenty-six million dollars in mining hardware over a couple different generations, all, manufactured in the USA. And, around mid twenty nineteen, we started to get really excited about the idea of building a Bitcoin hardware wallet. We actually were really inspired, by your podcast series with hardware wallets. I think that was around like summer of twenty nineteen."
    },
    {
      "speaker": "stephan",
      "time": "05:17",
      "start": 316.97,
      "text": "Yeah, yeah. And,"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "05:18",
      "start": 317.77,
      "text": "specifically that interview with Michael Flaxman where he was saying every Bitcoin hardware wallet sucks, and so a lot of those ideas resonated with us, and so we kind of just kept talking about it, and then ultimately, myself, Ken, and two of our other teammates decided to quit our jobs in the beginning of this year and- Start Foundation Devices with the goal of making the open hardware foundation for Bitcoin and a sovereign decentralized internet, starting with our first product, which is a Bitcoin hardware wallet called Passport."
    },
    {
      "speaker": "stephan",
      "time": "05:52",
      "start": 352.12,
      "text": "Gotcha. And Ken, let's hear a little bit from you also."
    },
    {
      "speaker": "guest_2",
      "time": "05:55",
      "start": 355.33,
      "text": "Yeah, sure. So my background is computer science, so I'm the software guy, software engineer and architect. so in my career, I've done things, everything from embedded systems and network protocols, device drivers, embedded databases, wrote a lot of C code, a lot of C++. worked for companies like Electronic Arts, Arista Networks. I worked for a high-frequency trading company in Manhattan, developing, data analysis and visualization tools. And around 2017, I kind of got interested in cryptocurrency, so I was a bit of a late bloomer, I guess. And I was interested in SiaCoin, which, was made by Nebulous. And as I got more interested in that, I got involved with the community there. I actually ended up, quitting my job at the high-frequency trading company and joining Opalesk as an employee. And while I was there, I was responsible for the firmware for the miners, the web-based user interface, I wrote the customer portal front end and back end, and actually I was a VP of sales too, which was interesting. So, also involved with a lot of, of customer, customers who are working to find co-location facilities to host their miners. And, yeah, I mean, over the, over the course of that project, brought two generations of software and hardware to market, as Zach was mentioning, and that brought us up to today where now I'm head of software for Foundation Devices."
    },
    {
      "speaker": "stephan",
      "time": "07:26",
      "start": 446.44,
      "text": "Great. And so, I just wanted to also touch on some of this obelisk stuff because there's been a little bit of chatter, and I just think it'd be good, Good opportunity to just address this and discuss that, also just to set that to give the listeners a bit of your perspective on what happened with Obelisk as well, because from what I've read, it seemed that there were some users complaining that they didn't get what they purchased, or-- and although I understand, you know, you weren't, you know, Zach, you weren't the CEO, you, you guys were working at this company, but could you just address some of those, kind of concerns that have been raised?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "07:58",
      "start": 477.56,
      "text": "Yeah, absolutely. So we're actually really proud of"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "08:04",
      "start": 483.53,
      "text": "Joined, I, I joined in right as the company was getting started as, as, an early employee in the summer of twenty seventeen, and as you know, later in that fall was the big crazy bull market, and so we launched this crowdfunding campaign for these ASIC miners, without even having like a, a photograph or an image or any, or any really information about the device, of, of what the device would look like. So we, we said, you know, give us money and, in twelve months From now, we'll give you a miner. And so, as you know, with a lot of hardware crowdfunding projects, they can often spiral out of control. that didn't happen here. So we actually shipped, every device that we sold, we shipped over twelve thousand, ASIC miners, as Ken mentioned across, two generations of chips and three generations of industrial design. and we, manufactured all of that in the US. we were an average of three or four months late, depending on the batch that you ordered from, right? So, we were saying we would ship by August thirty-first, I believe it was, of twenty eighteen, and I think the first shipment started going out in October or November, but we shipped everything, and it was all within about twenty or thirty percent, Towards the target spec that we were, that we were aiming for back when we started the sale. So I, I think, I think the, the main contention is that, the altcoin mining space is a total mess, and that's one of the reasons why we didn't wanna be in that space anymore, because it feels a lot like gambling. you can deliver exactly what you promise or really close to what you promise, but what actually matters is the price of these underlying, you know, cryptocurrencies, and then also the other mining manufacturers. and so, you know, Bitmain and Inosilicon ended up flooding the market, especially on the DCRD mining side, and none of the miners when they received their devices in twenty eighteen on the DCRD side made any money. So we did some cool stuff, you know, for example, we knew that, that when we shipped these devices, they probably weren't gonna be profitable for the DCRD miners, and so we, offered to do like buybacks so that you could at least recoup some of your money and you can, you know, choose to, reinvest that elsewhere. So we were, we were trying to be very, very friendly from a customer service perspective, we were extremely transparent throughout. So ultimately, we're, we're really proud of what we did and, and having, you know"
    },
    {
      "speaker": "stephan",
      "time": "10:45",
      "start": 644.92,
      "text": "Gotcha. Yeah, okay. and so perhaps you wanna also tell us a little bit more about, the adding of the foundation. And so how did that come about?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "10:57",
      "start": 656.61,
      "text": "Yeah, so we just felt this unshakable itch to be founders and to be working on Bitcoin. So I'll let Ken comment for himself personally, but for me personally, you know, when I got into Bitcoin, I was very interested in it from the decentralization and efficiency perspective. So I was all about, you know, let's, let's get rid of these intermediaries, let's get rid of these trusted third parties like banks and even, you know, governments, and let's just allow people to transact, you know- You know, directly peer to peer online. over time though, I started to go really down the rabbit hole from, you know, podcasts like this one and Tales from the Crypt, from books like The Bitcoin Standard, and I, I just got so enamored with the, with the Austrian economics perspective, right, and about Bitcoin being the perfect money. And so between that and then being really frustrated with the existing hardware wallets out there, and then also knowing that we as a team had the potential to just- design, better hardware than what exists on the market today. We just, we just felt like we had to do it. And so, we founded the company in, in mid-March, and we officially started the company in April of this year. we raised a little bit of money from some small funds and angel investors, and we worked from April, until, you know, until now, and, and we're at the point now where we're gonna be, manufacturing, in- In early or mid-January."
    },
    {
      "speaker": "guest_2",
      "time": "12:30",
      "start": 749.85,
      "text": "Yeah, I would just add to that, our experience, previous to that at Obelisk was that we were working like founders, but we weren't being, compensated or, you know, dealt with as founders. And so we felt like, okay, well, we can do all of this stuff on our own and actually be the founders and be the ones making the decisions, and then be responsible for those decisions. So that for me- Autonomy was a, was a big part too, just having the autonomy and, and the fact that we, those of us who, who moved on to Foundation all had really aligned goals, along the, the lines of what, Zach was talking about as far as Bitcoin and, and design and better hardware."
    },
    {
      "speaker": "stephan",
      "time": "13:15",
      "start": 795.22,
      "text": "Great. and so perhaps, you could just tell us a little bit about the team, as I understand there's, four main co-founders and, you're, you're slowly building the team up over time?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "13:26",
      "start": 805.73,
      "text": "Exactly. So I, like I mentioned before, have a background in mechanical engineering. I'm really obsessed with product design. I've always been obsessed with Apple as a company, and so, as you can imagine, as I've embraced Bitcoin and open source, I've fallen more and more out of love with Apple and hoping that we can do similar great hardware designs, but have it all open. And we also have Matt as one of our co-founders. He's our head of circuit engineering. he was at Intel for a few years. He has a- Bachelor's and masters in electrical and circuit engineering, and he's a little bit of a circuit prodigy. And then we also have Jacob, who's our head of supply chain, who was at Formlabs, previously. And then we have Ken, of course, as well here, who's, who's our head of software and has an extensive background, as he mentioned, in every layer of the stack from firmware up to actual, actually doing mobile apps."
    },
    {
      "speaker": "guest_2",
      "time": "14:18",
      "start": 858.19,
      "text": "Zach always tells me to shorten my intros because I keep talking too much, so that"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "14:22",
      "start": 862.33,
      "text": "was really, a really"
    },
    {
      "speaker": "guest_2",
      "time": "14:23",
      "start": 863.23,
      "text": "abbreviated intro that I gave."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "14:26",
      "start": 865.71,
      "text": "Yeah, and we're, and we're hoping, you know, we're hoping to grow the team. So far, we've done everything with, with our team of four. between the four of us, we, we can really hit, you know, every discipline of, of bringing hardware to market. a lot of the times, hardware teams struggle, especially on the supply chain and the operation stuff, you know, being able to actually source all these components and, and then manufacture them. We benefit from those experiences at Obelisk, where we did so much manufacturing in the US."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "14:55",
      "start": 895.45,
      "text": "suppliers and manufacturers here, and so Passport is actually being fully assembled, you know, the circuit boards and everything, fully assembled, in the USA, which is also something that we're, that we're really proud of."
    },
    {
      "speaker": "stephan",
      "time": "15:07",
      "start": 907.28,
      "text": "Cool. And, so I've had the chance to, use the demo unit also, perhaps you could just tell, the listeners, what are you trying to achieve with the Passport device itself, which is the first product?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "15:19",
      "start": 919.22,
      "text": "Yeah, so Passport is our effort to make hardware wallets as easy and secure as possible, while also giving you a device that you can feel proud of using, that feels elegant and up to the task, and maybe even worthy of your Bitcoin. So, you know, we've used all the hardware wallets, of course, over the years, and have been personally frustrated by whether it's, you know, difficulty using the devices, you know- For example, difficulty doing things as simple as entering a PIN number, to also being concerned from a security perspective about, not having a, an air gap. And I think Michael Flaxman probably explained all these shortcomings much better than we can, over a year ago on your podcast, but we think things like PSBTs are really important, having a true air gap is really important, allowing for really easy text entry and navigation to enc- Best practices when it comes to passphrases or other things like that is really important. So we just want to make a hardware wallet that is so easy to use that maybe we can actually pull users off of Coinbase and other centralized exchanges, and then also have this really great open source security model where not only is the firmware completely open, but the hardware designs themselves are completely open, both for auditability and then also so anyone can build off of our work."
    },
    {
      "speaker": "guest_2",
      "time": "16:47",
      "start": 1006.6,
      "text": "Right, I mean, we're seeing ahead here to, you know, Bitcoin exploding, and we, we just don't think any of the wallets out there today are really gonna get us to the hundreds of millions more people that are gonna be coming into Bitcoin. we just think we need to improve the user experience significantly to get those people on board."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "17:06",
      "start": 1025.68,
      "text": "Yeah, and we, we look at the hardware wallet space today as being very similar to the MP3 player space before the iPod came out. We're, we're not claiming that we're the iPod, but we're definitely striving to follow those similar principles in terms of design and, and UX, and we're just looking to make a product that millions of people can use and our- The biggest fear is that we're gonna see a massive amount of new users over the next few years during this bull market and then throughout this decade, and that because it's difficult to store your own coins, your own keys, we're gonna see all those users go to Coinbase or go into Grayscale or something like that. And it's already quite scary, right? Where I, I think, I think it's maybe it's over one percent of the Bitcoin supply, I think, is with Coinbase custody right now. And that's just not an environment that we want, and so we just wanna be able to provide users with actual sovereignty and ownership over their keys, but without them having to deal with a lot of the complexities and, you know, all the quirks of, of using today's generation of, of hardware wallets."
    },
    {
      "speaker": "stephan",
      "time": "18:26",
      "start": 1106.18,
      "text": "Cool. And so, one interesting aspect here is when you are doing a hardware wallet, some hardware wallet manufacturers in the space have chosen to try to provide the full stack, if you will, like, for example, Ledger Live or Trezor's Web Wallet, whereas other hardware wallet manufacturers have opted more to just say, \"No, we're just making the hardware, you go and use the wallet software.\" So tell us a little bit about your approach on that part."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "18:51",
      "start": 1131.42,
      "text": "Yeah, so our approach is definitely, the second approach and very much inspired by Coldcard's approach. we think that At its essence, hardware is a delivery mechanism for great software, and we think that the software developers that are working on all these different fantastic projects, whether that's Specter or Casa or whether it's, you know, the team at Unchained Capital or whether it's these newer multisig wallets like Lily or I think Nunchuck just came out a few weeks ago, there's so much innovation on the software side. You know, our goal as a As a hardware manufacturer, is to give all the software developers access to just a great device that they can really easily integrate with their applications and then provide their users with more security. Then what that does is, it, it allows for faster innovation on the software side. So for example, you know, Ledger's Live app only just added full node integration like a week ago, but you've seen so many other wallets that have full node integration Over the last few years, because when you're, you know, when you're more agile on the software side, you can move faster. So, you know, that I think is, is key and important to us. And then there's also the privacy concerns. You know, if you start to trap users into this ecosystem where you use your, you know, your cor- your, corresponding desktop app to also be a place where they can buy Bitcoin or other cryptocurrencies and then swap between them and all that kind of stuff, you start to create a wall called Garden. And you also start to collect a lot of data about these users. You know xpubs, you know IP addresses, you know all this information. We don't actually want any of this information. And so we try to carry that practice through even like our, our website and e-commerce store, and, and, you know, we self-host everything on WordPress or WooCommerce, we self-host our own analytics. We don't wanna be giving data to anyone, and, and we wanna be collecting the most minimal data as possible about our customers because they're serious privacy. concerns when you're building this kind of stuff."
    },
    {
      "speaker": "stephan",
      "time": "21:05",
      "start": 1265.28,
      "text": "Of course. And, I guess, look, I, I broadly agree with you, and I think, perhaps just to, might be fair to give a bit of a context there for some of the OG hardware manufacturers like Trezor and Ledger, I think, you know, they were started in a different era, you know, before some of the software that we have today is available. So I guess maybe part of it is like they had to do things a certain way because they were around at a time when the tool"
    },
    {
      "speaker": "stephan",
      "time": "21:31",
      "start": 1290.77,
      "text": "The tooling, and we have things like Specter Desktop, and we have things like, you know, BlueWallet, which we might chat a little bit about and some of that aspects, and certainly I think, the approach of kind of each- Party trying to specialize harder into their area and say, \"Okay, I'm a hardware manufacturer, and I'm just gonna, I'm just gonna focus on making the best possible hardware wallet I can.\" I think that makes a lot of sense to me. but, perhaps the challenge then is how do you make it all interoperable? And I suppose PSBT is part of the answer here, but, how, how do you kind of figure out and how do you think about working with the different wallets that are available out there?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "22:07",
      "start": 1327.46,
      "text": "Yeah, so I think PSBTs is definitely key here, and luckily there's been a lot of great work that's been done. when we actually started the company, you know, Passport uses QR codes as the primary means of communication to establish a really secure air gap. We didn't know what standard we would be using for QR codes. Luckily, Blockchain Commons, which is a nonprofit group in the space, was working on that And so they basically developed this, it's called U-R, I believe, Universal Resources Standard, and that's actually what we use, to have interoperability, with the QR codes."
    },
    {
      "speaker": "guest_2",
      "time": "22:50",
      "start": 1370.44,
      "text": "They're also working on other standards, to, to help hopefully make it easier for wallets to interoperate, both between the software and the hardware wallets. So we're part of the, the working groups there and, and keeping up with what they're working on and, you know, providing our input on what we think the standards should be."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "23:08",
      "start": 1388.43,
      "text": "So the goal is basically that, one, you know, we have a universal standard for communicating data over multiple QR codes with an air gap, and it looks like with this UR standard from Blockchain Commons, we've achieved that, and that's currently used by all the different wallets that are using QRs, whether that's Kobo, Specter, BlueWallet. Some of them are using, an, an earlier beta version, which is UR one point o, but they should all be upgrading to UR two point o. Over the next several months, which is like the final version released by Blockchain Commons. And then Blockchain Commons is also doing some other cool stuff like standardizing like the export, so that when you, go ahead and you export your xPubs, you're able to basically export, you know, all of your xPubs and your var-various derivation paths in like a single set of QR codes, 'cause right now it can be kind of complicated, you know, each software wallet kind of requires, an export from the hardware wallet in different formats. So with Passport, we actually have a cool menu to make it really easy to pair up Passport with all the different popular software wallets, but we're doing a lot of manual work on the backend to figure out, okay, you know, what, what format do they need this data in? So hopefully over the next several months, we'll be able to converge on a format for that as well, and then it gets really easy because you get to pretty instantly pair your hardware wallet with your software wallet, and then you get to pass data over multiple QR codes. With the same protocol, and then you can have like an explosion in, you know, air-gapped, single-sig and multi-sig hardware wallet transactions communicating with software wallets on desktop and on mobile."
    },
    {
      "speaker": "stephan",
      "time": "24:51",
      "start": 1490.56,
      "text": "Yeah, it's certainly a great vision, and, I suppose just now is probably a good time to just talk through at least my experience of, trialing the unit out. So I, you know, got a test unit, as I mentioned earlier, I, you know, put in the batteries, spun it up, and then at the start there was Verification of, genuine, you know, yeah, what's the word I'm looking for? Like, the verify on the website that this is a legitimate device, and then I spun up a, a small seed just with five dollars in it, as, as you guys had, and basically imported that into BlueWallet using the QR codes. And so when you do that, it, it, because the, the entire device is airgap, right? So everything is QR or SD card basically. And so I did it with a QR code and, Yeah, for me, from my perspective, I thought it was an interesting experience, certainly, very different to the typical, kind of plug in a USB or do the SD card aspect of it, and, yeah, BlueWallet picked it up very quickly. I think for me, it was just about kind of making sure you had the right lighting so the cameras could kind of talk to each other in a way. but once you kind of get through that, then the scanning, worked pretty simply as well. so I thought that was pretty There around, kind of how it's gonna work with multisig."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "26:13",
      "start": 1573.01,
      "text": "Yeah. So it works very similar for multisig to single sig. I think the biggest difference with multisig is that one, you typically have more data, and so that means more QR codes. Luckily, as you probably saw from Blue Wallet or Passport, they, they can pass QR codes back and forth pretty quickly. So, you know, you could pass, I, I, I believe for the test you were doing it, it- It's typically, for single sig, like two to four QR codes, and for multi sig, you know, it could be a bunch more, but even, holding up your phone to your hardware wallet for five to ten seconds is going to be much faster than passing a micro SD back and forth or plugging into, USB. And so we think the QR codes make it multi sig really great. And then the other big thing about multi sig is just, you know, of course, being able to import that quorum, of your different public keys and derivation paths so that you can actually verify addresses on device, and that's also something great that QR codes work for. It's really easy to pass that information to the device, in an air-gapped way using just a few, QR codes that are encoded with this UR two point o protocol. Yeah, and we'd"
    },
    {
      "speaker": "guest_2",
      "time": "27:32",
      "start": 1651.9,
      "text": "like to, to work with the wallets to figure out, you know, what the right format is there and, and just make it super simple. To import that quorum information."
    },
    {
      "speaker": "stephan",
      "time": "27:40",
      "start": 1660.43,
      "text": "Yeah, that's great, and I think that, certainly was, I think, you know, if you go back a year, one of the challenges, that, you know, Michael Flaxman and others were talking about was this idea of how do you make sure you actually have access to the change and that you're not, you know, signing to some quorum that doesn't include only your, say, three devices, things like that, whereas, as I understand, then once you register the other devices in the quorum, then that"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "28:09",
      "start": 1689.01,
      "text": "Exactly. And, one thing that we, we haven't been, we haven't looked at closely yet because we've been pretty heads down, but I did listen to your podcast with Stephan, from a couple weeks ago, and I believe Spectre Wallet is experimenting with the idea of when you display or you pass like an address, you're also passing the corresponding, derivation path for that address, and that makes it extremely easy to, verify that on the hardware wallet, that the address belongs to your device. Otherwise, what you end up having to do is you have to kind of like brute force or pre-derive a lot of different potential addresses on the hardware wallet in order to compare. But if you have the derivation path, you can just immediately go and check if the addresses match. So I think that maybe hopefully throughout twenty twenty-one, we'll see, some standards kind of form on that side to make it just brain dead simple to instantly verify that a single sig or multisig address belongs to the hardware wallet. And I do think that the various multisig services, you know, I, I hope all of them add this, in twenty twenty-one. Not all of them have the ability to, you know, export the multisig QR information to a hardware wallet. I know Specter does, I believe Unchained Capital, does now. I think they started that with Trezor, I think it's also supported with Cold- Gold card. I don't believe that Casa does at this time, I don't think that BlueWallet does either right now. So I think we'll see a lot of progress on that in twenty twenty-one, and hopefully by the end of, you know, next year, we'll just have really, really easy standards to just, you know, verify an address on the hardware wallet and get people used to that as part of the flow, 'cause I think that's something that people aren't really used to right now. You know, oftentimes you just quickly create a receiving address and then just, address, I think being able to quickly scan a QR code of that address from your own hardware wallet and get the thumbs up that that address belongs to you is gonna be a killer feature."
    },
    {
      "speaker": "stephan",
      "time": "30:18",
      "start": 1817.77,
      "text": "Back to the show in a moment after a message for the sponsors of the show, Unchained Capital are building Bitcoin native financial services, and for you hodlers out there who are looking for ways to improve your security and go to a multi-signature setup, Unchained Capital is a great option for you. They offer the multi-signature vault free if you- Set it up yourself with no setup and storage fees. However, if you want help with that, if you want the white glove treatment, they offer the concierge vault setup, so you can get a call or have multiple calls, have hardware wallets shipped out to you, have your questions answered, and as part of the service, as part of the product, you'll have a thousand dollars of Bitcoin deposited in your vault. Now, if you want a discount on that, use the code Livera. Unchained Capital also offer OTC purchases, and you can have those done directly into your new vault. So this is a great option if you are looking for a self-directed Bitcoin retirement account or if you're a company looking to move Bitcoin to treasury. Don't forget that Unchained Capital offer advanced business accounts which offer all sorts of features that can help you do this and manage this process. So go to unchaineddashcapital dot com to find out more. And finally, Lend at HodlHodl is a global Bitcoin-backed lending platform. It allows you to lend or borrow anonymously on your own terms. This is a peer-to-peer lending solution with a secure and transparent collateral storage system by providing unique multisig escrow for each deal. So HodlHodl is that partner in this lending transaction. And so if you have stablecoins lying around, you can go there and put up an offer to earn interest by lending. on lend at HodlHodl, or on the other hand, if you have bitcoins and you need some liquidity and you don't wanna sell, well, you can borrow stablecoins and keep on hodling. So with HodlHodl's lend platform, you set your own terms and put up offers depending on how long you want to borrow or lend and interest rates. It's a peer-to-peer system, so go and check it out at lend.hodlhdll.com. Back to the interview. Yeah, certainly, I think it's interesting to see the way, security in the space is quickly ramping up, and perhaps in the past some of these things were available only to professional level or very technically, highly technical wiz-- Bitcoin wizards, right? Whereas now, w- some of these things are coming down, the technical competence level requirements, and so it's kind of making some of these, you know, higher security aspects available to the everyman, or at least it's gonna start out with the more tech-savvy people. People. Now, I think some of the points that maybe some of the listeners might be thinking at this point is probably good to address. It's common that in the space, people want something to be battle tested before they trust it with any serious amount of funds. And so I guess, how are you thinking about that with, well, it's the first edition of a hardware wallet, people, listeners might be unclear that, oh, okay, I mean, it's the first edition, who knows if the first edition will really work? Maybe there'll be hardware security, hacks on it and things like Planning to sort of, get through that."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "33:23",
      "start": 2003.06,
      "text": "Yeah, I think that's definitely, very valid. And, I think there's a couple different things there. One is that, you know, users should definitely slowly, I think, adopt Passport, right? we're definitely not recommending that you go buy a Passport and then you throw all of your Sats onto it in a single sig setup, right? So I think multi-sig helps a lot there. there's definitely a need for another air-gapped multisig-friendly hardware wallet. in Michael Flaxman's latest guide, I'm pretty sure that for his, the, in his two of three multisig setup for the third key, he wasn't happy with any of the hardware wallets, and so he recommended, you know, creating a seed offline and storing that offline on paper or in metal. And so we hope that we can be that third option, and so that way, if there is a bug or if there is a vulnerability- Vulnerability, you know, it, it won't impact you, right? It won't cause loss of funds. There's a couple other things as well that we're doing. so one is the, the hardware architecture we're using isn't like invented by us. It's the same architecture that Coldcard and BitBox O2 use, which is when you have the standard microprocessor and then a secure element chip, and in this case, we're using the same secure element chip as both Coldcard and BitBox O2. And so from that perspective, you know, it's not like we've invented some new architecture. the open source component also really helps, because all of the hardware and all of the firmware is completely open. I think if we were closed source, then that would be a really, really hard sell. And then I'm not sure if, if Ken wants to add anything more about the firmware, but, we are having the Wallet Dot File guys do our security audit."
    },
    {
      "speaker": "guest_2",
      "time": "35:17",
      "start": 2117.41,
      "text": "Yeah, yeah, that was the, that was what I was gonna mention, is that, Yeah, we're, we're gonna basically make sure that the code is fully audited before we ship it to any customers. we take it s-pretty seriously though. We know it's, it's the first time, but like, we wanna store our Bitcoin on this thing too, so, you know, we're gonna make sure that we don't lose our money and we'll make sure that, that you don't lose your money."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "35:37",
      "start": 2137.23,
      "text": "Yeah, while we basically designed Passport from a hardware perspective from the ground up, and we started off with a fresh MicroPython project and did all of Firmware stuff, we have ported over a lot of Coldcard's open source firmware as well, including the code that they use to create the, the Bitcoin transactions, and we looked at a lot of the code that we used for communicating with the secure element and some of the security features too. And so one of the great things about open source, especially when you're dealing with, you know, GPL three code, which is very copy left code, where, you know, you open source your code and you only let other people use it if they're gonna open source their work In return. So one of the benefits of that is we haven't started completely from scratch, even though we've made a lot of changes, and that's why it's gonna be really important to have experts look at what we've done and, and test it out. We haven't just gone in, started completely from scratch, you know, and just messed around and put together some, you know, V1 of firmware that's completely untested. We, we've tried to use some building blocks and then architecture from existing devices so that we're We're not just, you know, flying blind here. hopefully, you know, that will, help us a lot and help us avoid, you know, rookie mistakes that you would expect from a new hardware wallet, manufacturer."
    },
    {
      "speaker": "guest_2",
      "time": "37:03",
      "start": 2222.74,
      "text": "Yeah. So we, we tried to use the things that were solid, more or less unchanged, and then anywhere that we thought we wanted to do something differently, we spent quite a bit of time thinking about what changes we were making, and the, you know, the security model around those. So, I think we-- I think we The audit has to say, and, you know, we're, we're planning to publish the result of that audit, as well."
    },
    {
      "speaker": "stephan",
      "time": "37:26",
      "start": 2246.48,
      "text": "Excellent. And I think another point that listeners might be thinking is it also takes kind of monitoring what's going on in the Bitcoin space. As, as a quick example, I, as I understand, there was a-- so as I'm sure you guys would know, there was that, SegWit vulnerability earlier in the year. Now technically, this had actually been disclosed, I believe it was, Instagibbs, Greg Sanders On the Bitcoin mailing list. And actually what happened earlier this year was Saleem Rashid had gone and done an exploit based on that, and so then that triggered off a round of Trezor updating their firmware and so on. So I guess the question I'm sort of getting to is, it essentially takes a lot of kind of following the space and knowing what's going on and of, at s- probably some level of familiarity with Bitcoin Core and Bitcoin Core code. So, how are you, looking at that and trying to stay on top of there?"
    },
    {
      "speaker": "guest_2",
      "time": "38:19",
      "start": 2298.89,
      "text": "Yeah, so I mean, Zach Zach has been really great about following the news side of things and then pointing me to things because I've been really heads down getting the code working. one of the things that I'll be doing in the coming few weeks though is going back over a lot of those, you know, issues that have been found over the time since we first started working on it and integrating, you know, some of the patches and addressing some of the vulnerabilities. But I've also, I've also started looking at some of the, you know, Bitcoin core just, just to sort of very, very familiar with it or not very familiar, just to get, you know, a cursory level of familiarity with the code before I can start diving in, but it's definitely on our list to get more familiar with that code and also we're looking to hire more people in the future, to help augment that knowledge."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "39:08",
      "start": 2348.05,
      "text": "Exactly. And then, you know, I think by, sharing some common code with Coldcard helps us a lot. And then just looking at, you know, all of the different updates from Ledger, from Trezor User from BitBox and from Coldcard on every release cycle has allowed us to get really comfortable with everything. So we started, the project, the software project in April, and so we're completely up to date with all the vulnerabilities from before April. And then over the next several weeks before we ship, as Ken mentioned, we're gonna be making sure that we address all the stuff that's happened since April. That SegWit vulnerability was definitely interesting, you know, where you, where you have to, you know, you- You can get someone to sign multiple transactions and then piece together, you know, basically a fraudulent transaction and, and steal their coins. Coldcard fixed that in an interesting way by storing a little bit, like a hash of, of the, of the transaction on the cold card. I know that also that vulnerability created a lot of controversy. I believe that was the same fix that caused Trezor to close down a lot of derivation paths, which broke compatibility with some various software wallets. And so we're really cognizant of As, as we, make sure that we're caught up with everything in the space and, and, and keeping track of all the vulnerabilities, we wanna make sure that we fix things in a way that makes the software wallet developers happy, as opposed to, you know, breaking any functionality, which was pr-pretty contentious, earlier this year. And I know like some things like BTC Pay were affected, you know, Casa was affected, a bunch of stuff was affected with how that specific- secret vulnerability was fixed."
    },
    {
      "speaker": "stephan",
      "time": "40:53",
      "start": 2453.28,
      "text": "Yeah. And also wanted to chat a little bit about seed generation and some of the different options available there. So can you tell us a little bit about the approach with seed generation and getting sufficient, entropy and sufficient randomness there?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "41:09",
      "start": 2468.71,
      "text": "Yeah, definitely. maybe I, I'll probably give just a higher level view of how we think about seeds, and then Ken can take us through some of the nitty-gritty, 'cause we do something different than all the other hardware wallets with our main source of entropy. The way we think about seeds, though, we kind of share Casa's perspective on this, where we think that for normal people, seeds are really challenging to deal with. Our ideal scenario is that we never show the seed to the user, and that's a different approach than what I think all the other hardware wallets take. The reason for that is because, you know, as Bitcoin scales to millions and hundreds of millions of people I think a majority of people still don't really know what the seed phrase represents, and if you look at the recent ledger and now trezor phishing scams going on right now, and I've actually clicked through these websites to test them out for fun, they, they typically revolve around tricking a user into entering their seed in a web browser. I think that that just doesn't work in the long term for a normal person to be expected to write down and- Manage these seeds. So I think multisig is really, really important there. And then one thing we're doing as well, which you didn't see in your demo because we haven't finished this feature yet, but it's the same way that Coldcard provides an option to do microSD backups, we actually include two industrial-grade microSD cards with every Passport purchase, and one of them is for users to, if they want, backup their device to the microSD card, and then, and that's encrypted, and they can write Down a few BIP thirty nine words, you know, off the word list in order to serve as the password to that SD card, but then they never actually see the seed, they never have to write down the seed. in order to get the seed out, you have to have both the micro SD card and the password, and I think that's a much better solution for the average user than writing the seed down. In terms of entropy, we have a few different sources of entropy in the device. We do have the embedded true random number generator and the secur- Element, we have the random number generator in the microprocessor, we also have an ambient light sensor, but we have something really, really cool called an avalanche noise source."
    },
    {
      "speaker": "guest_2",
      "time": "43:31",
      "start": 2610.52,
      "text": "Yeah, so what we did there is, following, some work by Bunny, it's basically a circuit which is a combination of basically off-the-shelf components like resistors and capacitors and whatnot, and the combination of these, components actually generates random noise, and we sample sampled the noise and then use that sampled noise, through a white-- run it through a whitening algorithm and come up with, random numbers. And we've, we've done some work running it through random number analysis, we're still doing some more work there, but it's, it's looking really, really good as a, a random source, on its own. And then what we're gonna do is basically probably combine that with the RNG on the MCU and the SE, and maybe the ambient light sensor, just to, to get Sources and combine them together."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "44:23",
      "start": 2662.7,
      "text": "And one of our like key philosophies as a company is to minimize or eliminate what we refer to in, in, Bunny, who's a like famous hardware hacker who's doing the B-Trusted and Precursor projects right now, what he refers to as black box silicon, meaning that in all these different electronic devices on the market, you have a ton of chips that are basically, executing black box firmware. So the chip itself is a black- Black box, because, you know, we can't, for example, go to ST Microelectronics, who makes our, our microprocessor, we can't go to them and say, \"Hey, can you like give us your chip design so that we can audit it?\" Right? That's a complete black box. And likewise, you know, we can't go to Microchip, who makes the secure element, and say, \"Hey, can you give us the design of the block on your chip that has the true random number generator?\" And so what's crazy in the electronics world is that pretty much every component has an embedded chip running unknown firmware. That's also true of most LCD screens and capacitive touch panels. And so, if you have a touch screen, for example, in a hardware wallet, it probably has two chips that are, that are running unknown firmware. And so, the great thing about using this avalanche noise source is that we're able to create entropy without trusting any black box silicon. And one of our design goals over the next, you know, probably few gens generations of Passport devices is to further and further reduce the use of black box silicon to the point where every single chip in the device is, is open or we know exactly, you know, what kind of code is, is running on that. And so that's something that we're just striving for from a philosophical perspective."
    },
    {
      "speaker": "stephan",
      "time": "46:08",
      "start": 2768.41,
      "text": "Admirable goal, I think, in terms of that, I, I also wanted to ask about the firmware and how firmware updates would be done, how would they be verified and, put in? To the new device, can you talk us through that process?"
    },
    {
      "speaker": "guest_2",
      "time": "46:24",
      "start": 2783.74,
      "text": "Sure. So what we're doing is we're only allowing firmware that's signed by Foundation, first of all, with a caveat that I'll mention later. So we're doing a scheme where we have two signatures, that are required for each firmware update, though. So let's say we have, five keys that are available, any two of those could sign a firmware update, and those would be held in different locations, and so it gives a bit of friction to creating a firmware update for us, which is something we want. so no, you know, for example, I couldn't go rogue and publish a firmware update on my own. It would take at least two of us to go rogue. and so the idea there is, is to provide that friction, and then, on the bootloader, the bootloader is the one that is in control of deciding when firmware can be installed or not. It will validate the signatures on the firmware, and, we have the, the blue and the green light on the device, and it will only turn the light green or blue, sorry, when the firmware has been, validated and confirmed that it was signed by Foundation devices. So that's the first thing. We are looking at, adding The ability for a customer to add their own signing key and keeping that key in the secure element, and that would be a way for, you know, really advanced users to build their own code, and load that onto the device. So if we were to, if we were to look at how that works, the user's gonna, you know, enter, get their key onto the, onto the device and load their firmware, through the SD card, and the bootloader will pause, on every boot if there's non-foundation firmware on there. So that, no user would be fooled in thinking that, hey, I'm running, I'm running legitimate foundation firmware here. There's always gonna be an indication that it was firmware that was loaded by a third party. We're also looking at a hardcore unit which would come completely unprogrammed. It would be probably a different SKU with a little bit different looking hardware, like maybe different colors, to the device and to the, the pr-printed circuit board, but that would come without a bootloader on it even. And so you could basically hook up your own JTAG programming device device and flash your own bootloader, flash your own firmware, and then decide to lock it down at any time if you wanted to do so. So maybe there'll be like ten or twenty people in, in the world that want that, but, we, we wanna be able to, to support those people if they, if they want to do that kind of, level of, of, va-validation and verification on their own."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "48:55",
      "start": 2934.64,
      "text": "Yeah, and one thing that's important to note is that, you know, even if you're using a hardware wallet that lets you build From source and install it onto the device. There's already a bootloader on the device that can't be changed. It's code that's loaded in at the factory and once it's there, it's permanently there on the device and it can't be updated with a firmware update. And so, you know, our design philosophy with the bootloader is to make it as minimal as possible so that it barely does anything except very basic functionality like figuring Out what firmware updates to allow, and then as Ken mentioned, there's definitely some tiny percent of users that just wanna load up their own bootloader, and so it's not too complicated for us to give that to users because it just means, you know, basically diverting a device at the factory that we would have programmed and sealed, we're just sending that off, you know, to a very advanced technical user, maybe with a little kit where they can hook it up to their computer and they can, you know, build everything from source themselves. So While we've made some key design decisions, you know, we're, we're restricting it only to allow firmware signed by Foundation devices, we are still, offering some of these power user features because we think from a sovereignty perspective that it's really, really important for the people that wanna be able to build their stuff from source, you know, they should be able to build that stuff from source, and we as a company should never stop them from doing that because then it's a very slippery slope to be like an apple like You know, Waldgarten."
    },
    {
      "speaker": "stephan",
      "time": "50:34",
      "start": 3033.87,
      "text": "Gotcha. Also thought it would be good to just talk a little bit about, in terms of, you know, attack surface of the device and so on. So, the main two methods that I've seen, as, you know, from using the device, you see, you've got the QR and the SD card. So can you talk to us a little bit about, you know, why you chose those methods and, you know, USB, not, not having USB?"
    },
    {
      "speaker": "guest_2",
      "time": "50:55",
      "start": 3054.98,
      "text": "Yeah, so I mean, we, we know that, Connecting it to the internet. So if there is any kind of, malware installed on that computer, it would have access potentially to data over the USB, and we just wanted to close down that completely as a potential attack vector. And we think like if you've got a mix, if you've got an airgapped unit, a airgapped wallet, but it also has a USB drive or yes sir, USB connector, there's just the, the ability for you to get lazy, you know? You, you don't, you don't wanna do it the airgap way today, so you In and then you get owned. So with Passport, that's just not even an option. So what we wanna do as a company is provide people with options that basically do the right thing and encourage them to do the right thing whenever possible, like the secure thing. And so this is a way we think that, that achieves that where the only way you can interact with the device is through micro SD card and through QR codes. So, we're, we're just cutting off entire, vectors for attack, and mistakes."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "52:01",
      "start": 3120.58,
      "text": "And ideally, when we first set out to do this, we, being kind of silly, and we didn't want to even put a micro SD card, slot on the device at all, because, you know, a micro SD card is almost like a mini computer. You know, you could, you could theoretically have a compromised micro SD card that has some tiny little chip or circuit on it or something that monitors or modifies the data that's being passed, but, the unfortunate truth is that That as of right now, you know, one, we're using MicroPython, and so, our firmware updates are just by nature going to be too large for QR codes to be, you know, we would love to be able to do a firmware update via QR codes. it seems kind of silly if you're, you know, talking about hundreds of QR codes, but if you're making some minimal changes to certain lines of code and you're able to just pass the delta, it could be possible on a future unit, especially if we try to move to something like, some kind of like QR codes or something like that in the future that can transmit a lot more data. So that's something that we're, you know, keeping our eyes on. And then, you know, just QR codes themselves are, are fantastic in terms of the auditability. You know, you can always scan the QR codes and you can really quickly through just numerous different software, either on mobile or on desktop, you can verify the output of that. So it's much, much harder to pass something malicious through QR codes. And then, you know, just to add on with what Ken- Ken was saying about USB and then maybe also Bluetooth, you know, there's so many Bluetooth vulnerabilities all the time. We, we really don't think a hardware wallet should have Bluetooth. You could just Google, you know, like Bluetooth vulnerabilities, I think there are like three this year or something like that that are pretty bad. And then with USB, you can do a lot of like tricky things with USB and, you know, very even basic, like, kind of dumb attacks that you wouldn't even expect. So, you know, like Ledger had a vulnerability, for example, where you could modify the, The, the normal MCU on the ledger, which is like the non-security chip on the device, and it could act as like a, like a keyboard. And so your, your first instinct might be like, you know, okay, like that's, that's a weird attack, you know, what's the big deal there? But if you combine those avenues of attacks with the types of phishing scams that we're seeing today, if you all of a sudden have the ability to, you know, open a web browser and take the user to a website, maybe You know, that website is actually malicious and is asking, you know, for your seed and it tricks some large number of users. And so we really don't think that USB or Bluetooth belong in a hardware wallet. We also kind of think that SD cards don't either, but I don't think we're at a place where it's possible to remove that. And as Ken was mentioning, our goal is to always encourage the best user behavior and not give, users any, any, any reason to trade off. Security for convenience, which is what technology like USB and Bluetooth does."
    },
    {
      "speaker": "stephan",
      "time": "55:06",
      "start": 3305.52,
      "text": "Gotcha. Turning now to the, I guess, the hardware wallet ecosystem and the security ecosystem as an, you know, as you've mentioned, you are aiming to be an open, you know, open software, open source, open hardware kind of, approach or where, where possible. So how are you thinking about, the contribution into the ecosystem? Is this, is there gonna be kind of like code contributions or, do you have any other considerations in mind there?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "55:31",
      "start": 3330.65,
      "text": "Yeah, absolutely. So one thing is we've already made all of our hardware designs open source under CERN's Open Hardware License, CERN being the research organization, you know, the one that makes like the large, hadron collider and other projects. So that's, that's a really great license, it's specifically designed for hardware. we're using the strong variant of their license, which is, very similar to GPL. it's a viral copy left Hardware license. So anyone is welcome to use our hardware designs as long as they open source, their work as well and preserve the copyright attribution. So what's great about that is that if, if you wanna come and you wanna use some of our hardware designs, if you wanna, for example, look at our implementation of the avalanche noise source, which we actually implemented from Bunny's, o h l, open source designs from Be Trusted, Anyone is welcome to do that and use that in their projects. And then likewise, we've also open sourced, the first alpha version of our firmware, you know, as GPL v3, which is also another, you know, viral, copyleft, open source license for software, so anyone is welcome to use that work. we have contributed, to the Blockchain Commons, UR, standard, can port it over the UR libraries to to Python and MicroPython, and so we've published that code as completely open source. Ken, is that under BSD? I think. Yeah, I think so."
    },
    {
      "speaker": "guest_2",
      "time": "57:10",
      "start": 3429.8,
      "text": "the, the one point o version I haven't published yet, but that'll be up this week. The two point o version is up, though."
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "57:16",
      "start": 3435.62,
      "text": "Yeah. So we've already done that. we've started to contribute a little bit financially to some of these open projects as well, so we're a very small monthly contributor to Blockchain Commons, and then if there's things we can do to make contributions back to other projects or even other hardware wallets like Coldcard, we're totally open and interested in doing so. However, you know, we-- each hardware wallet is, is designed differently, and so sometimes it can be really hard to just take code from one and move it to the other, you know, especially when you have different hardware, in the device, different components. Sometimes instead of just like doing a, a, a quick pull request, it looks more like, like porting work from project to project, but, you know, we're, we're totally, Open to that as well. And then we've also used, you know, other work and, and we've been really careful to give attribution to the different open source libraries. So if you go into our, our repo on GitHub for Passport firmware, and you can just get there from foundationdevices dot com slash passport-hyphen-firmware, it'll forward you over to GitHub, you'll see that we use, we, we give credit to Coldcard, we also use Trezor's crypto and Mod cryptocurrency libraries, so they have, you know, proper credit. An attribution in there. We use two different QR code libraries, and we have a pull request pending with one of them. You know, we, we mentioned the blockchain common stuff, so we're trying to be really careful and, and really good about giving, you know, attribution, to all the different open source work that we've built upon."
    },
    {
      "speaker": "stephan",
      "time": "58:46",
      "start": 3525.9,
      "text": "Gotcha. And, yeah, I mean, this is one of those spaces where there's always wars going on between different producers and makers of things, so I don't really wanna get into the drama of that, but,"
    },
    {
      "speaker": "stephan",
      "time": "59:00",
      "start": 3539.97,
      "text": "We are going on and, people would just be like, \"Hey, we're all gonna do well out of this, with a lot of people coming in and, if we all play nicely together, then, you know, maybe that, is a, a, a reasonable future that we can hope for.\" One other area to discuss is pricing of the device. So, on the website, it's listed, so the pre-order is listed as two ninety-nine USD. So can you tell us a little bit about, why this price point and It's not worth it for them, right? But who, who's the kind of person who it makes sense for?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "59:35",
      "start": 3575.34,
      "text": "Yeah, I mean, this, this makes sense for anyone who holds, you know, at least a few thousand dollars of Bitcoin or more, right? So this, this definitely doesn't make sense if you hold, you know, a thousand dollars of Bitcoin. And I think if, if you're going to do that, you know, and hold a smaller amount of Bitcoin, you're probably just gonna have it on, you know, Cash App or River or on one of these other services"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "01:00:00",
      "start": 3600.05,
      "text": "So we think that from a price point perspective, you know, it's not like we decided to start at this price point and then just, you know, that's it. We kind of worked at it from a first principles, perspective. it's more expensive to make a really high quality hardware design that uses, a larger screen that's more trustable. the screen actually is, is audit-able. It has, no embedded processor running unknown firmware, no black box silicon. So the screen is more expensive. We have a really high quality keypad experience that's more expensive. We use high quality plastics. We also have, the, the main structure of the device is, casted in zinc alloy and plated in real copper. we have a processor that I think is the fastest processor by a good margin in any hardware wallet. it's running at four hundred and eighty megahertz at its fastest, and, compared to Trezor's Model T, which is one twenty or Coldcard, which is eighty megahertz, it's significantly faster. That's both to run the camera And then also to just have, you know, faster processing of, of larger, PSBT transactions. And then we're also, assembling the device in the USA, and we're physically on the floor at our manufacturer. And so when you add all that stuff up, it does make for a more expensive product. Any hardware wallet with a QR code that is, you know, open source, that is, you know, running parts from reputable companies like STM or Microchip or Omnivision for the Camera sharp for the screen, it's going to be more expensive than your, you know, USB, your USB wallet with a small screen, and I think that's okay, because especially if Bitcoin, you know, finds itself in a really positive bull market scenario, I think paying a little bit more money for a much better user experience and a really great air gap, I think is a, is a no-brainer purchase."
    },
    {
      "speaker": "stephan",
      "time": "01:01:55",
      "start": 3715.04,
      "text": "Excellent. Well, I think, that's probably about all we've got time for for this one. It's probably a good spot to wrap up here. So, Zach and Ken, where can we find you online?"
    },
    {
      "speaker": "zach_herbert_ken_carpenter",
      "time": "01:02:03",
      "start": 3723.64,
      "text": "Yes, so, we're at foundationdevices dot com. We currently are accepting pre-orders for Passport. the, the official estimated ship date is March, 31st, but we will be, manufacturing in mid-January, and so hoping to ship out the devices, you know, as soon as possible in later January or early and we do a lot of blogging and, we talk more about open hardware on our blog and on our site. We have a weekly newsletter as well, so definitely hop on the site, check us out, give us a follow on, on Twitter, and, let us know, you know, if you have any feedback, you can always email us at hello at foundationdevices dot com."
    },
    {
      "speaker": "stephan",
      "time": "01:02:42",
      "start": 3762.22,
      "text": "Fantastic. Well, thank you very much, Zach and Ken, for joining me on the show today. Thanks."
    },
    {
      "speaker": "guest_2",
      "time": "01:02:47",
      "start": 3767.28,
      "text": "Yeah, thanks for having us."
    },
    {
      "speaker": "stephan",
      "time": "01:02:49",
      "start": 3769.02,
      "text": "I hope you found that interesting. I'm certainly finding it really great to see a lot of new multi-signature supporting options in the space, especially with QR, air gap, and so on. I was chatting with Zach and Ken afterwards, and they were interested to create a discount code for my listeners. So if you're interested to pre-order, go and use the code Livera, and you'll get a discount there when you pre-order. Your Passport device. I get nothing out of this, this is just a discount for you. So if you're interested, go and check them out there. Get the show notes at stephanelivera dot com slash two three eight for this one. Thanks, and I will see you in the citadels."
    }
  ]
}
