{
  "episodeId": "SLP310",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "charles_guillemet": {
      "name": "Charles Guillemet",
      "role": "guest",
      "tag": "CHARLES"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.69,
      "text": "Hi and welcome to Stephan Livera podcast, a show about Bitcoin. Today we're talking about Bitcoin software wallet insecurity and are you putting yourself at a lot more risk than you actually realize? I think this episode might, be very concerning for some people, but, we talk about some of the issues around software wallets and the security or insecurity of them and how keys can be exfiltrated. And so if you check out the blog post, which will be linked in the show notes, over on the Ledger Donjon blog, you'll see some very quick examples of keys being extracted out of faucets phones and desktop wallets and well known ones as well. So it's worthwhile thinking about and Charles Guillemet, he is working at Ledger, he's a well regarded security expert in the industry, and so he joins me on the show to talk about these issues as well as offer some tips and guidance for listeners out there who are looking to secure their Bitcoin. Now, the lead sponsor of SLP is Swan Bitcoin. Swan is the best way to accumulate Bitcoin with either lump sum purchases or setting up your automatic recurring buy, or as we like to call it Bitcoin savings plans. It's fast to set up and it's cheap to automate your stacking, especially for US customers, though Swan is available internationally and you can wire in funds that way also. Swan definitely takes a focus on education and content as well, so you'll notice that the more you know, the more you want it to buy and Also importantly, Swan is Bitcoin only, there's no confusion about altcoins. So come and sign up with Swan Bitcoin, go to swanbitcoin dot com slash livera, and you'll get ten dollars of Bitcoin dropped into your account when you start your stacking plan. Lend at HodlHodl is a peer-to-peer Bitcoin-backed lending platform so you can lend or borrow stablecoins globally and anonymously using Bitcoin as collateral. So with Lend at HodlHodl, if you need some fiat liquidity, you don't necessarily have to sell your Bitcoin. You can borrow stablecoins against your Bitcoin as It'll be held in escrow throughout the whole deal, while stablecoin owners can earn some extra interest by lending their stablecoins out and defining the terms and the APR for their deals. HodlHodl's lending platform is currently going through a major upgrade with improvements available soon, so go and sign up at lend.hodlholdl.com. It's been a very interesting year from a Bitcoin mining perspective, and if you are interested to get involved with Bitcoin mining yourself, CompassMining.io are here to help you. If you don't know where to source your equipment, well, you can go and purchase Dot io, and you can also have that machine sent to a facility that has been vetted by the team and has good power rates. And so many of us who can't mine at home because of the power rates that aren't cost effective, well, now you can with Compass Mining, and you can then select your mining pool, and you'll start receiving Sats. Compass's team will help you buy, ship, and install the important mining hardware that you will need to successfully mine Bitcoin. So if you want to get started, go to compassmining.io. And now onto the show with Charles. Charles. Charles, welcome back to the show."
    },
    {
      "speaker": "charles_guillemet",
      "time": "03:04",
      "start": 184.01,
      "text": "Hi, Stephan. Thanks for having me today. It's a pleasure to participate in the show."
    },
    {
      "speaker": "stephan",
      "time": "03:09",
      "start": 188.67,
      "text": "Yeah, and I know you've got a lot of cool things you're working on and doing, and often, obviously, thinking hard about security. And so I wanted to chat with you about some of these concepts, because I know you, you wrote a really cool post recently on Bitcoin software wallets and the security aspects of that, obviously compared with hardware wallets. Now, of course, people say, \"Oh, look, see, you work for Ledger, you're But I, I still think it's, it's worth a discussion just to kind of understand the different concepts, understand what's going on there. So from your perspective, when we're talking about Bitcoin security, what, what are the main challenges? Is, is it around protecting that secret or what's some of the main challenges?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "03:46",
      "start": 226.34,
      "text": "Yeah, the challenges are huge. let me, let me dezoom a little bit. blockchain technology is, is about to change the world. and this revolution can be compared to, internet revolution. It's a complete- Completely new, paradigm, in terms of adoption, Bitcoin, and more generally cryptocurrency adoption, we have today can be compared to internet in like nineteen ninety-eight. We are very early, so this is the first thing I, I wanted to say. second, blockchain revolution is about Changing the way humans, stores and exchange values, it's about decentralization, it's about self-sovereignty, it's about empowering people. This is huge. with Bitcoin, you really own your money, and it's something quite new. As long as you have your keys, you don't have to ask the permission from anyone to spend your Bitcoin. And it's, it's clearly a shift in the paradigm of, of money. when you use your bank account, when you want to make transfer, what you actually do is to ask the permission to your bank to use your money. Bitcoin is very different for, for, for that. and Your listeners probably know that already, but a quick recall about Bitcoin. Bitcoin is not an easy concept. at the end of the day, the coins you own are in the blockchain, they never leave the blockchain. So holding Bitcoin actually means being able to spend them. And to do so, as a holder, what you need is to hold your private key. And second, the blockchain is immutable. That means that you can't revert transaction. So when I said this, it's, it seems simple, but there are very, huge, security implication. That means that if you lose your keys, you lose your coins, and there is nothing you can do to revert that. If an attacker gets an access to your keys, he can make a transaction, and you lose, you lose everything. your key is a small piece of data It's like two hundred and fifty-six bits, but this bits, can secure one hundred USD worth of Bitcoin or billions in terms of information, it's the same thing. So I mean, I'm working in the security industry for years, and I was in the, in the security before working, the, the, this challenge is the biggest I know of. there was nothing, as, nothing, as big as this one in terms of security."
    },
    {
      "speaker": "stephan",
      "time": "06:21",
      "start": 380.81,
      "text": "Yeah, yeah, and so for listeners who are new obviously a lot of people listen to the show to learn, and so some are regular listeners and some are new. And so just for those new listeners, remember when Charles is saying there, coins don't leave the chain. Remember, it's a ledger, and you can think of it like your Bitcoin wallet holds a secret, and it can sign a message that allows the coins to move from one place on the ledger to another, if you will. And so the coins never leave the ledger. And so the point then is that you wanna se-- you really wanna secure that secret, because if only anybody gets to themselves, and you won't own that. And as we were talking, Bitcoin is immutable, the transactions aren't reversible, that's it, once it's out, it's gone, that is done. There's no takebacks, there's no bailouts, that's part of the Bitcoin system, and that's essentially part of what we accept. So I guess at the end of the day, we're trusting that our Bitcoin wallet and/or the device that we're using to operate that, whether it's a software device or a hardware wallet device, that it can keep that secret secure, because essentially it Your seed were-- is really like this big, big number, and then it, your wallet will kind of generate out the addresses and the keys based on that. So it's all about keeping that secret secure, isn't it?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "07:35",
      "start": 454.62,
      "text": "Yeah, definitely. Maybe we can, just talk very briefly about the basis of asymmetric cryptography. So asymmetric cryptography is a big branch of, cryptography. It involves a private key and a public key. The main application of, asymmetric cryptography is, digital- Digital signature. with digital signature, what you, what you do, what, when you sign something, you prove you actually know your private key without revealing any information on your private key. And anyone can verify that you know your private key without revealing it, just by knowing your public key. And this is the, this is the very, important principle of asymmetric crypt-cryptography, and this is what we, use for Bitcoin. When I send you, some Bitcoin, when I, what I do in a simple, in a simple way is to sign a message which proves I know my- My private key and anyone can verify that I know it because my public key is public. And in terms of Bitcoin, it's, anyone is the node verifying the protocol, running Bitcoin Core, and my public key is what we call addresses in, in the language of, of, of Bitcoin. So this is, this is basically how it works. I can send you Bitcoin to your public key, to your address, and just because I know my private key And I can prove to anyone that I know my private key, and this mechanism is, is called a digital signature. And maybe if I can do a, a very small parenthesis, we are We will go through, Bitcoin upgrade in a few months, yeah, weeks now. this, this Bitcoin upgrade is called Taproot, and Taproot comes with, new features, and one of them is We will change the way we sign transaction. Before, we were using an algorithm which is called, ECDSA on a curve which is called secp two hundred and fifty-six K one. We keep the same curve, but we will, we will use also a new, signature, algorithm, and this, signature algorithm is called Schnorr signature. it, it has a lot of interesting, benefits, like it's possible to do, to implement Twisted signature In a very simple manner. Also, the signature are, smaller and, yeah, th-th-these are the main, benefit that you, you, you get with Schnorr signature. So just to, to get back to, to, to the thing, owning Bitcoin means you are able to, spend them, and spending them means that you can produce digital signature, and to produce digital signature, you have to own your private key and never reveal it, because if you reveal it, that means that anyone- Else, who knows your private key, can do the same. It can spend your Bitcoin. So that's why it's paramount to secure your private key."
    },
    {
      "speaker": "stephan",
      "time": "10:40",
      "start": 639.54,
      "text": "Yeah. And I guess I should-- I mean, what we're saying here, we're focusing very much on protecting that seed, but I mean, I can think of other ideas related to Bitcoin security. Examples would be making sure that you truly control that receiving address, right? That somebody hasn't replaced the address with their address and you think you're sending Bitcoin to yourself. But actually it's somebody else, or you're withdrawing, or there might be other aspects around. Or another example would be making sure that when you create that private key, that seed, that you had sufficient entropy and that that process wasn't being tampered with in some way, or there wasn't some kind of malware or spyware going on. But I think just broadly speaking, the main, I guess, security considerations are protecting that secret and making sure that it doesn't get easily exfiltrated or stolen. And so in your article as well, you talked about a very interesting like spyware and- Malware, the Pegasus software by NSO Group, could you tell us a little bit about this? Because I think most people think, \"Oh, my phone is secure. It's, you know, Google and Apple, they make it secure, so I don't have to worry about these things.\""
    },
    {
      "speaker": "charles_guillemet",
      "time": "11:40",
      "start": 699.57,
      "text": "Yeah, you have to worry about that. The, the very l- short summary is, it's a very bad idea to use software, to use mobile phone or to use your desktop to secure your Bitcoin. frankly, it's, it's a very bad idea. But let's go into, into NSO. NSO is, company, a security company, and, let, let me, let me g-give you a small story about security vulnerability business, because this is what they do, in a way. when I was young, security research was mostly a game. Security Researchers were looking for vulnerabilities, and these vulnerabilities were simply shared on, free, for free on forums, also on security conference. this was on what we called at this time the dark web, but at this time the dark web was mostly, website with dark background. This is what we, what we called the dark web at this time. And, yeah, when, when you found vulnerabilities at this time, you just published them, on them, on these forums or going to, to- To, a conference explaining them. And this is what we call today, full disclosure, because you, you don't, you don't care, you just publish your vulnerability and, and company with, companies were quite unhappy with that, because that means that they were aware at the same time as ev-e-everyone that there were some vulnerability, on their product. So they started to incentivize, security researcher, to stop, doing that and instead to be contacted, beforehand. this, this is what we call, responsible disclosure. So this is a kind of, gentleman's agreement where companies, reward security researcher when they find vulnerabilities on their product. it protects users and it al-- it gives some time, to the company, to this company to patch the vulnerabilities be- before bad guys, actually, exploit the, this vulnerability. And at first, the, the, the rewards were very small. You, you can, you could get one hundred USD or so, th-th-this was the beginning of, of, of, of this market. But the stakes started to be high, and, different actors started to get very interested in, such ve-vulnerabilities. I'll be very explicit. these actors are mostly criminal organizations and also national state services. let's be, let's be quite direct This is, this is the main people interested in, in the vulnerabilities. Criminal organization search and exploit these vulnerabilities for profit. Di-directly, they can do ransomware, they can access to your bank account to get your password, to dump database and resell the database on, on dark web. If you don't intend to, respect the law, there are many ways to, get rich, with, security, vulnerabilities. Nation, nation state services, it's a bit different, of course. They are also interested in this vulnerability, but they mostly use them to spy whoever they want, quite easily and, and very closely. So if we go back to NSO, NSO is a company specialized in buying and finding such vulnerabilities, and they use them to build Automated tools such as, Pegasus. From a user perspective, Pegasus is a very simple software. It's a software, you launch it, you put the phone number of your victim, you click on hack, I don't know if it's, what is written on the button, but this is, this is something like that, and then you simply have full access to, the phone of your victim. I mean, there is nothing else to do. There is just in the software, there are many, exploit, vulnerability exploitation which can be Work any kind of, so, iOS or, Android phone remotely without any, user action. And then you have a full access to the mobile phone. Full access that means you can dump all the data inside the phone, you can use the credentials of your victim to access to, his favorite services, to his email, to, his, coinbase, account, all the credentials. You can also spy his screen and, keyboards and every single inputs, you can switch on his camera re-remotely, his microphone remotely whenever you want. this is the feature which, which is used, a lot by, by national state when they use, Pegasus. There has been a couple of scandal where, NSA have been caught, using this to, listen the microphone of the French president, for instance. there has been a scandal around that. So basically, you can do anything, on- The smartphone that you break, and from a user perspective, it's just click on the button. So if you have the software wallet on your phone, that means that an attacker with Pegasus, can still find, like, just clicking and, and then pick your data. if you log into your Coinbase account on any exchange, the attacker can simply use your credentials to empty your account. So this is what Pegasus is about. Pegasus is about buying and finding The large number of vulnerabilities and to package them into a software which is very simple from a user perspective, which allows the user, to hack any kind of, of, mobile phone remotely without any, user action. So this is what Pigasus is about."
    },
    {
      "speaker": "stephan",
      "time": "17:20",
      "start": 1040.43,
      "text": "Yeah. So, you mentioned as well, this is remotely, this doesn't even require-- 'cause I've heard of those things where, say, police or law enforcement have like a machine and they like plug in the, the phone And it's like, you need, you need physical access. So in this case, how is the remote hacking working? Like, does it translate-- does it happen over the phone network or is it like using a data connection or how does it actually achieve that?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "17:43",
      "start": 1062.56,
      "text": "Most of the time, it leveraged some, messaging vulnerabilities. Like your, your, messaging, application is always listening on the network, and instead of, sending you, well-formed message, the application will send you ill-formed message. Which will exploit, vulnerability in the iMessage, software, for instance, that can be a buffer overflow or something, when, when the message is received by your phone, the messaging app will parse this message and then it enters into, the iMessage, software, and if there is a vulnerability, then, you can you can implement a specific message which will be at the end of virus, some kind of malware, and, and you can gain a remote code execution. So this is the first thing. And when you have a remote code execution in iMessage, environment, it's not finished yet. You have to, find another exploit allowing you to have some privilege escalation, in order to become root, on the device. So all the time there is the, in order to- To have zero click, zero action, this is something like, using a messaging app. So this is the, this is the main threat vector. And then you have to, chain several different vulnerabilities in order to go out of this a message environment and to esc-escape the different countermeasures, because now there are plenty of countermeasures, to, to get out of the sandbox and so on and, finish root on the, on the devices. This isn't, this isn't simple, and this kind of vulnerability today is quite expensive because there is market for, vulnerabilities. And such, vulnerability, new one like zero-day, not known by, a, Apple or, or, or by Android, I, I didn't verify, but it's today, but it's, it's between one million and two millions, but You have one vulnerability and you can break all the phones in, in the world at once. So, it's, yeah, it's a question of market at the end. There is a cost opportunity here."
    },
    {
      "speaker": "stephan",
      "time": "19:54",
      "start": 1194.45,
      "text": "Yeah, that's very interesting and very scary for many people, because I'm sure a lot of listeners aren't familiar with this idea. So let me just walk through that some of that just to make sure everyone's following along. So the point here is that there are companies out there who, it is for them, it is very profitable to, you, find and purchase these exploits"
    },
    {
      "speaker": "stephan",
      "time": "20:15",
      "start": 1214.93,
      "text": "Someone else's phone. And as you were saying, the way these might typically operate is that they might have a bit of a foot in the door with the messaging service, and then once they're in, as you mentioned, there's this idea of chaining together multiple exploits. So at the start, you're getting in via the messaging application somehow, you're getting remote code execution on that person's phone, and now because phones are generally sandboxed or each application is sort of protected in a certain way, you mentioned this idea of privilege escalation. So it's this idea that Instead of only just getting in and being stuck in the sandbox, you need a way to kind of get in that sandbox and then escalate out of there and get what we call root access, meaning you can, you have god mode, you can see everything on the phone. And then at that point, if you're able to read someone's Bitcoin private key, boom, your coins are gonna get stolen. And so I wonder then, why haven't we seen more of these attacks in the wild? Because I'm sure there are lots of people who are using Bitcoin phone wallets today, with hot, with keys Daron hasn't been pointed on this yet, or is it just not profitable or feasible for them to do that kind of attack yet?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "21:21",
      "start": 1281.42,
      "text": "F-First of all, it already exists. there are plenty of examples where, where people, get stolen on their software wallet. Most of the time, it's, it's mostly used, in a targeted mode. I know that you have on your phone like one million, so it can be interested, interesting to, to break your phone. It's not always zero-click, maybe I can just send you a, a link and then there is a vulnerability in your Chrome and then I can do, sandbox escape and so on. So this is the first thing, so it already exists, it's not large scale yet. The second thing is there is an opportunity cost. the thing is There's vulnerabilities, there's software aren't free, and you have to make sure that, that the investment you do in either, finding vulnerabilities or, buying them, will be, the cost will be lower than, what you, what you gain at the end, because as soon as you, you start to, use this kind of exploit, they get detected, and then there, there are some teams, in, in Apple or Android who, inspect what's going on And then they find the vulnerabilities and they, they patch their software. This is called what, what we say, this is burning a vulnerability. It's, you, you actually burn it. So there is this opportunity cost. It, and today, criminal organization can get really more money, with easier mean. Like you do phishing attacks, it's, it costs nothing, it doesn't need any kind of knowledge, and if-- and for now, it works very well. So as long as it's- Easier to do phishing attack rather than doing that, it's, attackers will prefer to, to use, phishing attacks. But my fear is Bitcoin and cryptocurrency will grow like crazy. This isn't, this isn't a, a question, this is the, this is what is, what's going on, so, the, the, the history will tell, but this is what, what's, what, what's isn't going. So the adoption will grow like crazy, and at some point, I fear that if The adoption go through, too much through, through software wallet, the opportunity cost will be very, very profitable, and spending like one million, two million, ten millions will be nothing compared to, what you can earn using this, this wallet. And from my perspective, it's It's, it's a systemic risk. I mean, if an attacker can, like, put fifty million on the table and is able to wipe every single software wallet in the world in a few minutes, he will get, like, hundred, maybe thousand, maybe more, Bitcoin And that means that it's a s-s-systematic risk, a systemic risk, because if an attacker can, can get a large proportion of, Bitcoin supply, it's not good for Bitcoin at all. So that's why I, I'm a bit frighten, frightened by, by that. On the other hand, I think that hardware wallet and, secure, secure solution will, will prevail, at the end, because Yeah, it's, it's not a good idea to, to use software wallet, so, we have to, continue the education and to explain, what's, what's going on, what are the stakes, and to explain this kind of threat, because, because this, this isn't a new threat, it will happen. As soon as the opportunity cost is positive, this kind of attacks, will happen in the field. Right."
    },
    {
      "speaker": "stephan",
      "time": "24:53",
      "start": 1492.9,
      "text": "Yes. And I mean, it's probably, for all we know, it could even be profitable today, but"
    },
    {
      "speaker": "stephan",
      "time": "25:00",
      "start": 1500.39,
      "text": "There would probably be a lot of users out there using some of the well-known wallets, right? Let's say even if it was just Blockchain dot com or Blockchain dot info's wallet or wallets where it's known that the keys are hot, whether it's a Lightning wallet or it's a CoinJoin wallet that requires keys to be hot, there would obviously be a lot of money sitting on all of those devices, and so if the attacker is able to get the number of, or find out who has those devices and obviously pay the money to get that information, this would be a very, very profitable attack, and Something to be concerned about. And as you were saying though, for now, that's not the lowest hanging fruit, and they will go after that, right? They might go try and buy a list and, you know, email phishing, and because there's enough, I guess, unfortunately, gullible people who will respond to the phishing kind of attacks, and in some cases they are quite good, so it's not even that you're gullible, that they, they could have just been really good. So I guess the other question I wanted to ask as well, while we're on Burn the vulnerability and only use it to, as an example, they don't wanna spend two million dollars to buy a vulnerability and only make fifty thousand dollars out of the hack of, out, out of that, because now they've burned that vulnerability, and then that means in the next version of Apple iOS and in the next version of Android smartphone, they will patch that. And so how much of it is a defense that, you know, there's patching going on, or also is there use of certain more hardened operating systems you might have heard of on Android, for example, there's Graphene OS and Use Calyx OS and things like that. How much does patching and the use of these alternatives help?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "26:35",
      "start": 1595.29,
      "text": "First of all, y-y-you know, there is, there is the zero-day, market, vulnerability, zero-day vulnerability market, and this is what we were talking about. But frankly, most of the smartphones are not up-to, up-to-date. This is the first thing. So they are vulnerable right now, this is not tomorrow, this is right now. So I'm going to be very fast on this one, and, to everyone who listens should use software wallets. I, I think this is, this is as simple as that. If you do that, this is exactly as if you put a banknote in the street. This is what, what it is about. Software wallets are fundamentally insecure. Every day there are vulnerabilities on your browser, on your operating system, on the software running on your computer. it's clearly too simple to hack a computer. I mean, this is a, this isn't something complex. this is a, this is a something for students. So don't put, valuable information in it, and especially not, cryptocurrency. And also to those who, use offline computer, first of all, it's clearly something not convenient at all, if you, if you have some time, I encourage you also to read the story of, Stecnet. you probably know Stecnet. In very short, Stecnet, is a worm, designed by the NSA. They are everywhere. to win, to wound, the nuclear program of Iran. they simply infected the air-gapped computer, located in bunkers, which were, controlling the nuclear plant and, and more specifically, the nuclear centrifuges, in order to, to make uranium, concentrated. I don't know if it's English, but yeah, this is the idea. and it allowed to-- it allowed them to physically break all the centrifuges. So this showed So this story is, is, fascinating, you, you should have a look. But what I want to, to highlight is that even a high-end computer can be broken remotely without, physical access and so on. this is, this is something we, you, you have to have in mind. And using software wallets is definitely not a good idea for, security reason. I understand what you say about Lightning, and Lightning cannot, cannot be used, offline. You cannot have a hardware wallet for, for Lightning. but I think it's a different use case. You, you, you can see it exactly as your banknote, okay, it's not that secure, you can lose it, but you have to, to have this in mind. And, and the, also there is also a, a difference because, because with software you can do, attacks at, at scale. I mean, if, if I, if I want to, to steal your, physical wallet, I have to, to go near to you and to, But if I want to steal all the physical wallet at scale, it's complex. But when it comes to software, it's not that complex. So yeah, frankly I'm a bit, I don't know what to say because I would like to, I would love that, Lightning, grows and so on. But I fear that at some point, the whole system would be, vulnerable to, to such attacks. And, and I'm sorry to say that, but the today there is no, there is no real wallet We haven't countermeasures to, to counteract this kind of attacks."
    },
    {
      "speaker": "stephan",
      "time": "30:02",
      "start": 1801.78,
      "text": "Back to the show after a message for the sponsors. If you are sitting on a, with your coins on a custodian or on a single signature wallet, there's some urgency. You've gotta upgrade your Bitcoin security. Think about Unchain Capital. They've got multi-signature and they're making it easy for you. They've got a two of three vault setup, and you hold two, they would hold one, and they can also sign for you in the case that you're unable to reach one of your keys. We need to eliminate single points of failure, and that's essentially what multisig helps us do. And so you can order your own hardware devices and go to unchain dot com and set it up yourself, or you can go and use the VaultConseil service where they will ship you some hardware devices, they'll do a call with you, get you set up, even if you've never held your own Bitcoin private keys before, and you will then be set up with a multisig vault, and you'll have some Bitcoin dropped into your vault also. So if you go to unchain dot com, select And use the code LIVERA for a discount. And while we're talking about Bitcoin security, my favorite Bitcoin hardware device is the Coldcard. The Coldcard is one of the most recommended devices by Bitcoiners out there, and it really teaches you, as part of the process of learning to use a Coldcard, you'll actually learn a bit more about Bitcoin. And so it's a really excellent tool, both for learning and for security. You can use it in a single signature context or as part of a multi-signature setup, even with, say, Unchained. And they've got all sorts The ability to use seed XOR, which is a plausibly deniable means of storing secrets in two or more parts and each behaves and looks just like the original secret. Now, I noticed some people can be a bit afraid about using cold cards, but it's really not that difficult. Just get a wallet like Sparrow or Spectre and use, use it and just give it a try. There's all sorts of videos and guides also, so go to CoinKite dot com and use the code Livera to order your cold card. And don't forget about backing up your coins. CipherSafe dot io You'll get those twelve or twenty-four seed words, and you need to use a metal seed backup product so that you don't lose that access to those coins if something happens to your hardware wallet or that piece of paper, right? So don't trust that piece of paper, use a metal product. The CipherGrid is a new product coming out, you get everything you need for fifty-nine dollars. It's got privacy by default, you can lock it with a padlock, you get an automatic center punch provided so you can stamp in those words, and it's fireproof, rustproof, and waterproof. So To get a discount on yours. Back to the show. Yeah, that's unfortunate. And, yeah, that's, sad to see. But I, I suppose we should also talk a little bit about some of the different elements of security, because, in the, in the post, you talked through a few different ideas. So, for example, you've got like evil maid attacks, this concept of protection at rest and protection during secret use. So it'd be great if we could talk through some of those. So maybe if we could just start with this idea of an evil maid attack"
    },
    {
      "speaker": "charles_guillemet",
      "time": "32:58",
      "start": 1977.7,
      "text": "Different types of, requirements. So I think everything starts with the key generation. Generating good quality secrets isn't that easy, but it's paramount, if your secret isn't well generated, an attacker could leverage the bias, to guess your secret. In our case, we are using Sequellement to do so. They embed, dedicated piece of hardware to generate high quality random, and the, this kind of, random Number generator comply with the highest standards and certification. Yes, there are standards for randomness, this is something which exists. So I think this is, this is the, this is the first thing which is, which is important in the chain of security. The second is, protection at rest, this is also very important. The question is, is the following: you just huddle your Bitcoin, you just don't spend on, on nothing, and an attacker breaks into your house and hack, or hack your computer Smartphone, remotely, are you, are your keys, still safe? So this is, this is what it is about. And, what we know is that all wallets are not equal. for instance, what I, what I said before with software wallets If an attacker, gets an access to your so- to your, to your smartphone, your keys are, are secure only if you are using like a very long password, but long, long like crazy, and, and this is only for protection at first, when, when you start to, input your, your passwords, things, things are changing. And even for, hardware wallets All the, the, the, the wallets are not equals. they, they, they are the famous, Trezor and KeepKey, this kind of hardware wallets, it's possible to extract the content, of your, of this kind of hardware wallet quite easily, but in this case, you need, you need, a physical access to the device and so on. So at the end, hardware wallets are always better than software. this is, I, I'm not saying the contrary, and Trezor secure elements to, to avoid this kind of attack, and this kind of circuit are, designed especially for security and especially to resist to an attacker with a physical access, to, to, to device and with a high potential. And when it comes to, to smartphone or desktop computer, if you have a ph-physical access, it's just finished, except if every- everything is encrypted with, a high quality, password, if you have a physical access It says it's, it's simply finished. Then there is, protection that you use. So holding is one thing, but you, also need to receive and to send your Bitcoin, and this type of protection is, is also paramount. And, yeah, I'm, I'm about to send a transaction to you to send Bitcoin to you. So that means I, I'm about to sign a transaction with my private key, re-remember? So the question is, how can I be sure that? I actually sign the transaction that I intend to, so this is something important. And two, to ensure that, you need some trusted display. The trusted display is in the equation, because otherwise, if you consent to sign transaction and the actual transaction which is signed isn't the one you, you wanted, you have an issue. So hardware wallet, have a dedicated screen especially for this to verify what you sign. So when with a hardware wallet, when you want to, sign a transaction, the transaction is prepared on your, favorite, software companion wallet, let's say, it, it prepares the transaction, send it to your hardware wallet, and then you are about, okay, I'm, I'm about to, to send zero point one Bitcoin to, your address. I can verify everything, I consent and And the hardware wallet will sign the transaction. This is what, what we call the, whiz, whiz, whizzy whiz. what, what you see is what you sign. So this is something very important, and this is something you can't achieve, with a mobile phone, nor a, a desktop computer, because you have many different, programs which run at the same time and which could intercept what you are doing and change the display. You, you can't, you can't, be Be sure on, anything about, about this, this software. Then we have, supply chain attack, this is also something important. as a user, you receive your device, how can you be sure it's a genuine one? in our case, what we did is to implement an attestation mechanism, within the device, so it's, what we call a certificate, maybe, exactly on, on, like on HTTPS when you have the lock. on, on your browser, that means that there is a certificate which has been signed. so this is what we put inside, each single, hardware that we ship, and this s-certificates can be used to prove that the device is genuine. So it's a cryptographically proof, cryptographic proof, it can't be faked. But, in practice Unfortunately, it's not sufficient. the main issue we have today with, our new customers is that they don't know what to expect when they receive, the package, and it's a big issue because, for instance, we saw this a couple of times, in, in the past, some attackers we sell, some, hardware wallets, and, instead of, we sell it like a new device, what they di- what they did is initialize it with a seed And, and they even, bought some scratching recovery sheet, and when the user receive, the device, as he doesn't know what to expect He has the device already initialized, he has the scratching sheet, he scratch the, the sheet and, and which reveals, is, twenty four words, and if, if things this is the normal way to, operate a hardware wallet. And this is the, this is a very big, issue, and this is not easy to tackle because, there is nothing technical which will solve this issue, this is not the technical. So this is about education, explaining how the things work And also explaining these things before the users, started journey, in, in Bitcoin and cryptocurrency. So this is, this isn't something easy and, and we have seen a couple of, those attacks, in, in the past. And the last one is, evil maid attack. So this is a very famous kind of attack where an attacker gets, physical access to your device, like your maid, and, he gets, your device and he can modify it and then he, he can replace it and at the end he can put it back where, it was, without the victim noti- noticing, the, the, the difference. And in practice, it's quite difficult to be, bulletproof against this kind of scenario, because you can always imagine, scenario where, for instance, a fake device Which is very similar to yours, which we-- it, it will only wait for you to input your PIN and transmit your PIN to the attacker, and the, the attacker has your device and then he has your PIN and it's finished. So against this kind of attack, it's very, very difficult to be, to be bulletproof. there are a few things that we can do, but at the end, this is the, this is the very difficult to, to tackle this kind of, of scenario. And, generally speaking, fortunately these, scenarios are, very unlikely and, and, yeah. This is the, the, these are the, the five different, requirement to be secure and the security is not easy, as you can see."
    },
    {
      "speaker": "stephan",
      "time": "41:23",
      "start": 2483.47,
      "text": "Yeah, yeah. some of the stuff is very scary as well in terms of being able to take the secret while in use, right? So as, I mean, I guess going back to, I guess those two points that you were mentioning, one is protection at rest, so just hodling, you just have the keys. How easy is it for somebody to take that secret? And in the case of software wallets, it might be that somebody's trying to brute force to access your coins. And so then at that point, it's about how long and how secure is your password, and most people So remember very long passwords, and that's why we talk about using password managers, don't reuse your passwords across different services, things like that. But then the more scary one is protection during use. So in the post, you actually ex-show some video examples, very short examples, where basically you were able to demonstrate picking out that secret while it was in memory and in use. So I guess then, is it True to say that, you know, protection while in use is actually more difficult than protection at rest."
    },
    {
      "speaker": "charles_guillemet",
      "time": "42:25",
      "start": 2545.27,
      "text": "Yeah, because protection at rest, so let's say in the, in the software wallet on your smartphone, let's say you have a strong protection, for your seed at rest, like either a crazy long, password or you are using strongbox on Android or something, at rest we can say it's secure. But as soon as you want to, make a transaction or to, generate a receiving address, the software will need, to decrypt, your seed And that means that at some point your seed will be in plain, in your memory. And, if you are in a situation where there is a malware on your mobile phone, like a regular situation, the malware can, can have a look to what's going on in the memory and then can access to the seed when it's in plain, and as soon as it has the, the seed, it can just send it on over the internet. the, these are the videos we demonstrated in, in the past."
    },
    {
      "speaker": "stephan",
      "time": "43:24",
      "start": 2604.44,
      "text": "Yeah. And so in that post, the listeners who haven't seen it seen it. There is, there are some examples both on smartphone wallets and on desktop wallets. So I think the desktop example was Electrum, which is obviously a very well-known, wallet, and then some of the smartphone ones, I think it was a Coinbase wallet and also maybe Blockchain. I think maybe Blockchain.info or Blockchain.com, that wallet."
    },
    {
      "speaker": "charles_guillemet",
      "time": "43:44",
      "start": 2623.91,
      "text": "And, and also MetaMask, I guess. The, the thing is, I, I don't want to, this isn't a question of \"Does wallet which would be insecure.\" This is the, the fact that software wallet running on desktop or Mobile phone are insecure. This isn't about MetaMask or Coinbase or, or, or this one. This is just about the model. The model is not secure and, and you, you have to, to, to keep this in mind."
    },
    {
      "speaker": "stephan",
      "time": "44:08",
      "start": 2648.08,
      "text": "Yeah, very, very scary stuff, and I think it's challenging because many people in the space who aren't you, they won't necessarily be committed to go and buy a hardware wallet at the start. And so often the typical recommendation for people is to start on a phone wallet or maybe a software wallet on the desktop. But I guess the mitigating factor would be don't put too much on that and just use it while you're learning, and then once it's ready, that's when you, you need to start upgrading to using hardware devices and maybe for larger amounts you should be thinking about multi-signature"
    },
    {
      "speaker": "stephan",
      "time": "44:38",
      "start": 2677.76,
      "text": "It's this idea that whenever you open your wallet and it needs to sign a message, o- boom, all of a sudden, yeah, it can just be taken from you in your, in the memory of your phone, and because it's there in plaintext. Now, I guess the other factor that people might bring up is the example of having a trusted execution environment or some kind of secure element in the phone. So how much does that help, or does that not help at all?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "45:02",
      "start": 2701.98,
      "text": "Yeah, smartphones are a little better than desktop for security. I, I have to be, to- To be honest, and that, this is the case, they offer a couple of interesting security mechanism like app isolation, like key store, keychain, according to the, to your, your, your platform, and also, as, the two zone. Two zone is an interesting mechanism. nevertheless, there are many issues, with those. first of all, most of the software wallet on smarto-smartphone we studied don't use this security feature, so they exist on your mobile Mobile, but the, the software wallet don't use them. I will tell you why. The thing is that if you have a Samsung twenty-one, Galaxy twenty-one, or if you have a very old, phone, the blockchain wallet, blockchain dot com wallet must run on, on your phone and must be compatible with your phone. And with, with a, a old low entry level, phone, there is no Trezor, there is no Strongbox, there is so On, only for this reason, it's not possible to be compatible with any kind of phone and leverage the security mechanism. So this is the first thing. the second thing is even if you say, \"Okay, I'm use my, my software wallet is only compatible with the last version of, of iPhone and the last version of the Samsung Galaxy 21.\" The thing is that these mechanisms, as of today, don't implement the Bitcoin cryptography natively. So that, that, that means that you can't use them out of the box. You can't say, okay, I, I will implement all the security part with cryptography inside, the security enclave, and, I'm fine. The problem is as it doesn't implement, this, this cryptography, your software wallet will need to, to do something. Okay, I need to Sign a Bitcoin transaction, I will ask to, a strong box, let's say, or keychain, to release the key, and then you have the key, in plain, and then you sign the transaction. So you lose the, security at use, w-w-w-what we mentioned before. And also Even if your, your keys were safe, in the keychain or the key store, the smartphone don't offer the secure display mechanism. So when you consent to transaction What you consent is to unlock your keychain or your, your key store, but you don't not, you, you don't consent securely to, to sign the transaction of zero point one Bitcoin to this address. So the consent is quite different. And as you don't have the secure display, okay, on, on your mobile, you can see, okay, I'm sending zero point one Bitcoin to you, but in fact, I'm sending my wallet to, the attacker. And when I, when I consent, this is what, what it is about. So this is, this is also an issue, you don't have the security play, so, you, you, you can't, you can't, a, a, have this property. And finally, the thing is that most of this mechanism, not all, they are often broken, because security is, is something which, which evolve and, you need to be up to date all the time and so"
    },
    {
      "speaker": "charles_guillemet",
      "time": "48:28",
      "start": 2907.55,
      "text": "the thing is, it's difficult to stay up to date on every single platform, every single, security mechanism, across, across the, the board. So, so th-this is the, the, the difficult part. I think from a technology perspective, it might be possible to design, such device dedicated to that with, with an Android or something, with some trusted display and, and secure execution for, for your Bitcoin, Bitcoin cryptography. But doing it out of the box on any kind of, mobile phone is just simply impossible today."
    },
    {
      "speaker": "stephan",
      "time": "49:08",
      "start": 2947.87,
      "text": "Yeah, interesting. So essentially it would be possible to design a phone that might be more secure, but by that point it's almost like maybe you're just better off getting a hardware wallet because now you're doing that, doing it that way. But maybe in the future there would be more work done to make it accessible for people who are just getting started and to have it as a smartphone wallet, like a small amount of coins or something like that. And, as you were saying,"
    },
    {
      "speaker": "charles_guillemet",
      "time": "49:31",
      "start": 2971.33,
      "text": "the problem is to, is to be, a very open platform like Android is and iOS That is where there are, millions of applications and when you can do a-anything you want on the internet and so on, it's great. But when it comes to security, you, you want to have something, small that you master everything. And, yeah, I think this is the, the, the big difficulty, we have today, for, for this kind of wallet."
    },
    {
      "speaker": "stephan",
      "time": "49:58",
      "start": 2997.53,
      "text": "Yeah, I see. So y- in your view then, it's unlikely that there's much progress in that direction of people trying to make smartphones more secure or maybe to make smartphones have Or trusted, you know, secure environment that can handle Bitcoin's cryptography, you would say that's probably a bit less likely than a more of a specialized pathway, let's say the world goes down this pathway of, okay, we're just gonna have to do hardware wallet security better and better and better."
    },
    {
      "speaker": "charles_guillemet",
      "time": "50:21",
      "start": 3021.49,
      "text": "As I said be-before, the smartphones are getting more secure when the, the time goes. But the thing is attackers get better as well, like, and, and there is, for now, there is no time where, the security was, was, greater than the attackers. So the, it, it didn't happen. so today it's, when, when you see the, the last version of the ex- of exploiting iOS and something It's quite complex. They, they implement very complex thing to do, to, to, to chain different vulnerabilities and to go out of this, to do sandbox escape, then privilege escalation, then, and so on. So it's, it's quite complex, but all the time they, they succeed. So I think it will, it will, the security will incre-increase, but as the stakes are getting higher, it's, it's difficult to stay secure. And as I mentioned just before, if you want to have something To be secure, you have to keep it simple and stupid. this is the, some, some, Unix, motto, 'cause, keep it simple and, and stupid, and it's okay, it's, it's very correct for, for security as well."
    },
    {
      "speaker": "stephan",
      "time": "51:33",
      "start": 3093.43,
      "text": "Yeah. And so then bringing it back to hardware wallets and how they compare, let's say how hard is it or difficult is it to have malware on a hardware wallet? Or maybe that's not the right model, maybe it's more about-- maybe it's just introducing another- A different type of risk, right? It's like supply chain risk. Or as an example with software, there's this idea that you can verify signatures or you can have reproducible builds, and that's one technique that people can use in software to make sure they're running the right software. But I guess that kind of technique is harder, it's not possible with hardware, right? You can't run a PGB or GPG verify on a hardware device. So I guess it's, we're, we're choosing our poison a little bit in terms of which one, which risk are we having to accept"
    },
    {
      "speaker": "charles_guillemet",
      "time": "52:16",
      "start": 3136.21,
      "text": "Yeah, definitely. And I think the, the hardware wallets are more secure than any other solution, mostly because they are very simple and they do only one thing, just hardware wallet. They, they implement cryptography for, for Bitcoin, they implement Bitcoin application, and that's it. You can't load your, favorite Bitcoin ticker, you can't load Angry Birds or I don't know. There is only one thing you can do, only this. There is a, a very simple way to input thing, A very simple way to output things, and that's it. So this is the, the main reason why, a hardware wallet are, are more secure. So also there are, there are plenty of different hardware wallet project, and, I think it's, it's very good, for, for, for many reason. first of all, I think several choices is good for Bitcoin, it's good for the ecosystem in general, it's good for this decentralization. And, also, hardware wallet remains the best options when it comes to security. So having be- several choices, is, is, is good. there are, there are different legitimate options, and, in, in the, in the past, I, we had a look to a couple of them. So I, I can, give you some, insight on, what, what we had a look. And again, for the large majority of, hardware, there is no, no real, software threat because there is mo- it's not possible to run malware or, or something very, there, there are some enclaves and, and they are separated to, to, to from your, your, your phone or, or your desktop. We had a look to, Shift Crypto Finance, and I liked, a lot this, this project. they, they worked hard on innovation and, and so on. So this is a, this is a project I, I like. I'm not sure if, if they are continuing to, to contribute and so on. It's a long time I, I didn't, hear about, about them, but, but this is a project that, I liked at this time when, when I had a Also, I'd, I'd like to mention, my friend Rodolfo from, from Coldcard. I like the no compromise with anything. this is something I like with him. and, the good part for, for with this kind of, hardware wallets is that at the end, when you use your Coldcard, you understand Bitcoin. This isn't something for newbie, this is not newbie friendly at all. But I think it's, it's an interesting option because it forces you to understand you have to do your own research, you have to understand how it works, otherwise you can't use, this kind of, of hardware, hardware wallet. So that's why I, I like this, this project. It won't ever be a large scale project because of this. for mass adoption, you, you need to do some trade-off, and u-UX. I think a very smooth and, simple UX is, is something important that you don't have on, on Coldcard. I ho-often discuss with, Rodolfo, and all the time I request him to support Ethereum, but he's not motivated. Maybe next time, next time we discuss with him, you should suggest, this to him."
    },
    {
      "speaker": "stephan",
      "time": "55:31",
      "start": 3331.24,
      "text": "Definitely, definitely not. but yeah, I, I Coincard is a sponsor of my show, so I'm, I'm always, talking about Coincard. It's my favorite of the hardware wallets. But, yeah, I think i-it is, there's a lot to think about, and I think at the end of the day, the take home message is Left desiring about their security, and I think, just because we were mentioning it earlier, just so listeners are aware, the examples with the exploits that you ran through in that, in this post, which obviously I'll include in the show notes, there, it was an example where the user was downloading a Bitcoin Ticker widget application, and this ticker widget application was the one that then did, like, was able to basically sniff the key out in memory and then display on the screen, \"Here is the twelve word seed, seed words, or here is the seed word.\" The words and the PIN for this wallet on the phone, and so it's very scary for people out there who are thinking about their security, and especially if you are securing large amounts of coin on your phone, you've got to really be careful about that, and I think that's where you wanna think carefully and maybe only keep a small amount on your phone just for, if you're using, say, a small amount for a Lightning day-to-day use, little amounts, a couple hundred bucks, basically an amount of money that you won't cry about if you lose it, and then for, for the real Techniques are becoming more and more necessary. So I guess Charles, do you have any, final thoughts for the listeners, anything for them to keep in mind as they're learning about Bitcoin or security, and of course, where can people find you online and Ledger online?"
    },
    {
      "speaker": "charles_guillemet",
      "time": "57:03",
      "start": 3422.96,
      "text": "Yes, maybe a couple of, recommendation, about security. So the first of all, the first one is something I repeat all the time, but I need to repeat it again. Never, ever share your twenty-three words. I say it again and again because, we hear very often, customer or people in the ecosystem who get fished by people who do clever, phishing, attacks and they finish to, give their, their twenty favors and when it's, gone, it's gone. so th-th-this would be, this would be my, my main recommendation. the second one is to do your own research. I, I know this is something you say often in, in the show and I think it's- It's important, Bitcoin technology, blockchain technology is something very new. In ten years, let's say, it will be straightforward for anyone, but now it's not straightforward because this isn't something we are used to, to, to, to, to, to have, in, in our day-to-day life, except both of us, but regular people or newcomers who, who, who go in this ecosystem, they don't know what, what, what it's about and it's a new paradigm. So You have to do your own research and, and understand, what's going on. and, maybe the final one is, is when you use your wallet, always verify what you are doing on, on the device, because otherwise, if, if you just want to sign, you don't know what you do. so trusted display is something important, so you have to use it, and to finish with, I would say let's continue to enjoy the bull run, this is, quite refreshing."
    },
    {
      "speaker": "stephan",
      "time": "58:46",
      "start": 3526.29,
      "text": "Haha, excellent. Well, thank you very much, Charles. It was, very educational to talk with you today. Cool, thank you, Stephan. So some strong words there from Charles, and I'm curious to see what listeners are thinking, whether they are now more concerned about using software wallets, especially after seeing the video demonstrations on the blog post or just from hearing Charles's explanations around that. And I guess it's also an interesting point to manage how much should be kept on a hot wallet in terms of Lightning or CoinJoin wallets, where obviously the keys need To remain hot. Anyway, get the show notes at stephanilivera dot com slash three ten and make sure you share the show with your friends and families so they learn about Bitcoin too. Thanks, and I'll see you in the citadels."
    }
  ]
}
