{
  "episodeId": "SLP462",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "craig_raw": {
      "name": "Craig Raw",
      "role": "guest",
      "tag": "CRAIG"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:09",
      "start": 8.57,
      "text": "Hi, you're listening to Stephan Livera podcast, a show about Bitcoin and Austrian economics, brought to you by Swan Bitcoin. Use swan dot com and the Swan app for safe and easy Bitcoin buys. With Swan, it's really easy to set up a recurring purchase plan, so whether that's daily, weekly, monthly, you can accumulate just a set amount of Bitcoin and just automatically stack it into your Or in self custody. Now swan dot com also offers one time buys, also known as smash buys, so this can be useful if the price has just dipped and you really feel like taking a little chunk or buying a lump sum. Also, swan dot com offers free custody in your own legally owned trust account, but of course, not your keys, not your coins. There is also free automated withdrawals to self custody. So if you go to swan dot com, there's all kinds of free resources that you can use to learn about Bitcoin. One favorite of mine is Inventing Bitcoin by Yann Pritzker, you can get this by going to swan dot com slash free book and you'll get a copy. It's a really easy one, short book to read, and it explains a little bit about Bitcoin and how it works. Are you ready for something big? BTC Prague is coming up June 8th to 10th. It's going to be in Prague, in Czech Republic. This is going to be the biggest Bitcoin event in Europe, and you've got to come and check it out. Make sure you check your calendar, put it in your diary, check out the"
    },
    {
      "speaker": "stephan",
      "time": "01:30",
      "start": 90.14,
      "text": "But I'm really looking forward to BTC Prague. I'm gonna be one of the MCs. There's gonna be an awesome lineup of speakers. There is gonna be a range of experiences available. There'll just be the standard tickets available or the industry ticket with an extra one-day business conference. It'll be more bi-b2b focused, and there'll be industry leaders presenting tools, ideas, and experiences. Or for the whales, those of you who want access to unique whale zones with the stylish environment, there'll be chances for networking and meetings, as well as premium food and drinks and an exclusive party event So to get your ticket, go to btcprague dot com, use code livera for a discount. When it comes to Bitcoin block explorers, mempool dot space is the place to go. I use mempool dot space when I'm about to send an on-chain transaction, just so that I can check what kind of fee I need to assign with my transaction. Now, mempool dot space shows you a range of things. It can show you where's this mempool, it can show you the blockchain, it can show you second layer networks like Liquid, and recently, the Lightning Network. With mem"
    },
    {
      "speaker": "stephan",
      "time": "02:30",
      "start": 150.0,
      "text": "You can host it yourself. Now, if you're with an enterprise, Mempool.space offers customized mempool instances. You can have your company's branding, increased API limits, and more. Go to mempool.space/enterprise. So for today's show, my friend Craig Raw of Sparrow Wallet re-joins me on the show. We chat a little bit about multi-signature security and privacy, as well as Bitcoin developments in the space."
    },
    {
      "speaker": "craig_raw",
      "time": "02:54",
      "start": 174.09,
      "text": "Craig, welcome back to the show. Great, Stefan, it's, it's really good to be back."
    },
    {
      "speaker": "stephan",
      "time": "02:58",
      "start": 178.26,
      "text": "Yeah, there's been so many updates going on with Sparrow Wallet, and I thought it'd be great to have you back to chat about the space, whether it's multi-signature or privacy or import and export of transactions. I think there's lots of things to add. So, yeah, I'm just curious, as you look at the space now, what are some of the big things on your mind, just kind of more broadly?"
    },
    {
      "speaker": "craig_raw",
      "time": "03:20",
      "start": 199.81,
      "text": "Well, I think, you know"
    },
    {
      "speaker": "craig_raw",
      "time": "03:24",
      "start": 203.73,
      "text": "From, certainly from my point of view with all of the sort of ordinal stuff, particularly, you know, I, I don't think it's a, it's a massive really impact on Bitcoin itself, to be honest, apart from the fee rate being a little bit higher, but for myself personally, Sparrow has been recommended, as, as the sort of go-to wallet for many of the ordinals users, so it's certainly changed my world a little bit. But that said, you know, it is what it is, and yeah, we go on."
    },
    {
      "speaker": "stephan",
      "time": "03:54",
      "start": 234.09,
      "text": "Yeah, right. And as I understand, that's because, well, probably because firstly Sparrow is easy to use, but also I think it, it might be the ease of being able to freeze a particular UTXO, which is, useful for the ordinals people where they, if they've got a rare Satoshi or an inscription tied to a particular sat, I presume from their point of view that's why Sparrow is being recommended for them."
    },
    {
      "speaker": "craig_raw",
      "time": "04:17",
      "start": 256.68,
      "text": "Yeah, I think that that's definitely part, part of it. I think also just the ease of being able to create a Taproot wallet is, I think, a big part, part of it. That's the required wallet to be able to, to use it. So I, I think that it was just sort of a ease of use thing and became an early recommendation for that reason. Yeah, I see, I see."
    },
    {
      "speaker": "stephan",
      "time": "04:35",
      "start": 274.81,
      "text": "Well, I mean, it's, it's a cool thing for you, obviously, seeing your product be, used by more, more and more people. Like, I guess, you know, it's kind of like, you know, if you look at Joe Rogan or things like people, they might have multiple audiences, right? Like, he might have the people who follow him for comedy, then people who are into MMA and all the other stuff or general. So maybe for yourself, it's like Sparrow is there for people who are, People."
    },
    {
      "speaker": "craig_raw",
      "time": "05:04",
      "start": 304.35,
      "text": "Yeah, I, I think that, you know, I certainly have no issue with people using Sparrow for these different use cases. I will say that ordinals isn't particularly my interest in the world, and I don't intend to be building Sparrow along those, those lines. And I'm seeing a number of, of other, you know, new wallets coming to the fore now who are gonna try and cater towards that, and that's great, you know, people should build stuff and they should use the stuff that caters towards the particular use case that they're trying to address. Sparrow remains very much, you know, focused on financial self-sovereignty. It remains focused on, you know, making your-- making it easy to self-custody your funds and keep your, your, your funds private as you spend. So, you know, that's gonna remain what Sparrow does, and if people want to use it for other things, that's great as well."
    },
    {
      "speaker": "stephan",
      "time": "05:55",
      "start": 354.9,
      "text": "Excellent. And so I think the other cool thing with Sparrow is that you can really start basic and then work your way up, right? And I think that's a really interesting- An important thing for people out there when you're getting started, I think it can be very overwhelming, and I've seen this even with listeners or followers who DM me at times, and I'm, I'm sort of coaching them through saying, okay, take this step now, take this step, and I think, that's a useful thing. So I'm curious, how you're seeing that journey for a new Bitcoiner or, let's say the, the person who is just learning about self-custody, can you talk through a little bit of maybe any insights you're Sparrow, who are going on that journey."
    },
    {
      "speaker": "craig_raw",
      "time": "06:35",
      "start": 395.39,
      "text": "Sure. So, you know, it's, it's actually quite interesting having the Audinals users come in because they rarely don't read anything at all. It looks like they've literally spent five minutes, you know, on the entire thing and then, you know, committed money to it, which, which is quite a remarkable thing actually. it's quite different from your average Bitcoin user who generally spends quite a bit more, more time, thinking about things before they, they kind of make the first plunge, Even with, you know, much less funds at stake. So I think that that's been quite an interesting thing, but certainly, you know, it's been okay to see how Sparrow has handled that, you know, it, it hasn't, you know, always been straight, straightforward. I mean, you know, there's a little toggle at the bottom of the Sparrow status bar where you can connect and dis- disconnect from whatever server you are configured for, and, you know, there's a, a three screen dialog when you first inst- install it Which kind of explains what this thing does, and that is not even being read or, or seen by, by some. So I mean, you know, there, there is sort of a level to which you actually can't really improve things, you can only, you know, guide people to a certain extent, and then you need to rely on them kind of reading some degree of documentation or the help presented by the application. So I, I, I think from, from that point of view, the sort of most basic point of view I'm reasonably happy where things, things are. From the more advanced point of view, you know, a lot of the last year has been spent building out the, the more advanced use cases, and that continues to be the case, you know, just trying to make sure that people trying to do various, I would say, less common but nevertheless, valid use, use cases are catered for, you know, just trying to fill in all the sort of gaps, o-one of the, the, the, the most recent ones that I've actually been working on this week This week is being able to do remote multi-sig setups, so, you know, when you're not in the same, same room, you can still set up a multi-sig, and there are formats that cater towards that."
    },
    {
      "speaker": "stephan",
      "time": "08:45",
      "start": 525.01,
      "text": "Yeah, so let's talk a little bit about that. So I guess You know, users who are just getting started, you might start with a single signature wallet, maybe you, you know, you just start with that, with no passphrase and just basic, and then maybe some users are deciding, okay, I'm gonna go single signature with a passphrase, and of course, I think the more advanced level is to get to multi-signature. Now, I'm a big fan of multi-signature, I, you know, I use multi-signature myself, and so there can be some practical difficulties or things you have to learn to deal with when you're in a multi-signature"
    },
    {
      "speaker": "stephan",
      "time": "09:18",
      "start": 557.78,
      "text": "Hardware device in a different location, and if you're going to, let's say, a vault, and maybe the Q-- you're trying to do QR scanning, you know, these are some of the practical difficulties, I guess. So can you talk to us a little bit about what that looks like if you're doing a Sparrow multi-sig and you've got keys in different locations?"
    },
    {
      "speaker": "craig_raw",
      "time": "09:37",
      "start": 576.59,
      "text": "Yeah, sure. So I mean, look, that's generally not too hard, you know? I think, you know, you might need to, if it's a QR code, you'll obviously need to take"
    },
    {
      "speaker": "craig_raw",
      "time": "09:48",
      "start": 587.66,
      "text": "Scan from that device. In terms of some of the other ways you can do it, for instance, if you have a cold card and you're using it in air gap fashion, you can walk in without anything really, just a sort of SD-- The micro SD card, yeah. Correct, yeah. And then just sign with that. So there are a few different options, and I think it's quite interesting to be able to consider which, which ones might be better, but I mean, they're not really impactful. I don't think if you have a safe custody lo-location, walking in With your laptop is necessarily a difficult thing to do. I think the, the, the most key thing around multi-sign and this is nothing new, is that apart from the backups of the seeds of all the individual de-devices or at least a quorum of them, so two of, of the three if you're in a two of three, you also need a description of the wallet. You need to have all of the public keys, and this is because you need to be able to recreate the spending s- script whenever you want to spend, and that contains the public keys to that address. And that means basically that you need to do this in one of two ways. Either create backups of your wallet file, so in this case, your Sparrow wallet file, or you need to have the output descriptor, which is some-something that Sparrow now presents to the user when they first create their multi-sig wallet. So there's a dialog that pops up and it shows you the sort of long string And then the idea is you can either print this out as a PDF, you can write it down, whatever means you feel is most secure and caters towards whatever you need. And then if you need to restore your wallet, you can basically just plug that in, and your entire wallet will then pop up, all of the funds will then come, and so long as you still have a quorum of the devices, you'll be able to sign and send."
    },
    {
      "speaker": "stephan",
      "time": "11:40",
      "start": 699.77,
      "text": "Right. And so, yeah, as you mentioned, this output descriptor, this wallet backup, it's a crucial step, and it's important to- Have multiple copies of that. of course, there is a privacy consideration with where and how you save that. for example, if you're keeping it in the cloud, you might want to encrypt that first. If you are having it maybe on some USB sticks along with your devices, maybe you wanna be careful which places you keep that because obviously there's a privacy ramification, but it's also important from a redundancy point of view to have it so that you don't lose access to your coins, of course. So, what are some of the, I guess, other- practical aspects of offline signing in a multi-sign context, I, I know for example, QR signing can be a little difficult depending on the lighting in the room, the devices that we are using. Are you seeing any innovation or developments on that front?"
    },
    {
      "speaker": "craig_raw",
      "time": "12:34",
      "start": 753.95,
      "text": "Yeah, I mean, I think, you know, the most interesting one recently in, in terms of the QR stuff is, the launch of the new-- well, the upcoming launch, I should say, of the new CoinKite, you know, the, the, the se- The Q1. The Q1, yes, which, you know, I, I think is going to be interesting. I'm still uncertain exactly what format that's going to use. most, devices in the industry now use a format called UR, which is sort of a, a compact format that we use to send data back and forth. So we'll, we'll just have to see how that goes. In terms of, you know, devices being able to scan, yes, there are definitely times, where it is e- Easier. I've heard one trick is actually to, you know, hold up a sheet of white paper behind the device. I don't know how much mileage you might get out of that, but, that is certainly some-something that I've held. The reality is that some devices, and here I will mention the Jade, are just their, their screens are just very small, and it's always going to be difficult for a laptop camera, which is usually not as proficient as a phone camera, to be able to scan such a small- Screen. So there are some devices which are better than others, and, you know, devices like the Passport, have really been designed for it, you know, that's, that's their kind of primary means. So with those kind of device devices, particularly if you're using the sort of newer sort of version two, it's much, much, much better. So, you know, it really, I think, depends to some extent on the device that you use. The Seed Sign also generally tends to be pretty good. You don't really have any issues there."
    },
    {
      "speaker": "stephan",
      "time": "14:15",
      "start": 855.0,
      "text": "Yeah, There's also some development and discussion around changing the density of that QR code, so I, I presume that instead means if you have it as a lower density QR, it just needs to do more different QRs in a, in a GIF format or something similar to that. So that's also something we've seen as well, right?"
    },
    {
      "speaker": "craig_raw",
      "time": "14:36",
      "start": 876.07,
      "text": "Yeah, I mean, that's, that's right. You know, i-it's basically the way that these animated QRs work is that you have this sequence of QRs and you can- Pick up a s-stream of them, and then the app-application can then figure out from that stream, you know, all of the information that it needs. And if you decrease the dens-density, you're gonna have a longer stream. In other words, you're gonna have to scan for more, more time, but you'll have-- you will need less resolution in the actual scan in every image that, that you scan, because the actual blocks in the QR code will of course be bigger. So, you know, it's, it's sort of trading off the speed of being able to scan versus This is the really the ability to recognize the QR codes."
    },
    {
      "speaker": "stephan",
      "time": "15:21",
      "start": 920.78,
      "text": "And one other thing I've seen is general ongoing debates in the community, online discussion, people saying, \"Oh no, don't push people into multi-sig, it's too complicated, a lot of people are going to shoot themselves in the foot, just do a single signature wallet with a passphrase.\" And then there are others who are in the more pro-multi-sig camp where they're saying, \"No, actually it's a big improvement in your security, it's worth it, you just have to remember, okay, keep it simple.\" Don't do anything too complex. I'm curious if you have any view on that. Do you see that as multisig is a ne- is a real necessity above a certain value, a certain number of coins, or how are you, you know, how would you advise somebody to whether they are deciding on just single signature with a passphrase versus actually take the time, learn to do multisig? Sure."
    },
    {
      "speaker": "craig_raw",
      "time": "16:08",
      "start": 968.19,
      "text": "So I think that, you know, first of all, let me talk, talk about the pass, passphrase. I think the passphrase, you know, I would still- I consider an advanced feature. the reason I say that, is because the passphrase is something you bring. So looking at the security paradigm of something that I own plus something that I bring is, you know, generally a good way of seeing things, and the passphrase, of course, is something that as human beings we need to recall and enter in. Now, we may have made a record of it, but really, you know, if you've just written it down underneath your seed words, you haven't really achieved Anything because your seed words are already enough to create a, seed with enough entropy in it. So it's really som-something that you at least meant to store in a different place if you do store-store it, but otherwise you need to really recall it in your head. And of course, as human beings, we have a tendency to forget-get things or enter them in wrong, and that's really the reason behind a recent Sparrow feature which essentially displays not only the master fingerprint but also a little image. Which is unique to that, and that kind of allows you, as you type your passphrase in, to be able to see and kind of match up in your, in your mind both from a, a fingerprint recognition, but also from a visual cue, you know, whether I've entered the right passphrase. Because again, if you forget whatever passphrase it is, you have lost access to those funds. And I think that that's a very real, you know, thing that a lot of the people who use and recommend the passphrase, you know, that, That to many beginners seems like a, a very different paradigm from the normal one where you enter in a password and if you get it wrong, you get told that you entered it wrong. Whereas with a pass- passphrase, you enter it in, and whatever passphrase you enter creates a valid wallet. And I think that that's a big difference that a lot of people don't fully understand. Right, it can be confusing. Correct, yeah. So, so I, that's the way that the standard is designed, and that's the way that it works, you know? So, so we all- Following it, but I think a lot of people don't fully un-understand it and, and, and how that sort of impacts them. For example, they will create a wallet, enter their passphrase, have a typo in it, and then send funds to that, and then close the wallet, and then when they get, get back, they, they don't obviously re-enter the typo, but then those funds that they sent are gone, and that's a common thing that you might see, and that's really what this, this kind of life hash, this little visual cue, is helpful for. So That was a little sort of yellow with some gray lines, lines on it. That looks like the one that I have. So that's, I think, you know, just talking a little bit about past prices, getting to the multi-sig thing, you know, I would say you'll do multi-sig when you feel you need it, and there's no feeling like the security in my mind of knowing you have a multi-sig setup, you've got multiple devices in different areas, and you can deal with the fact that one or more of them can be lost. Lost can be completely destroyed and you can still have access to your funds. So, you know, when do you get to that point? I think it's when you are worried about it, when you are lying awake at night thinking, you know, I need to do better. The value of this to me, whatever the amount is, the value of this to me is high enough that my cold card sitting in the, in the sort of cupboard or the safe, plus the passphrase in my head, just doesn't feel like a secure enough, answer for For me, I need something a little bit better, and that for me is when the sort of multi-sig comes in, and it, it is, I think, easier. You know, there are people out, out there who will say it's hard, and I think that, you know, if you, if you don't do the, the, the correct backups, then you are getting yourself into trouble, you know? But I think that so long as you have, you know, backups of the seed, seed words for each device, plus you have a backup, as we were saying"
    },
    {
      "speaker": "craig_raw",
      "time": "20:16",
      "start": 1216.14,
      "text": "Different locations, and you have a good, obviously a good password on that file, then I think that it's actually a relatively easy thing, you know, and certainly, you know, it's, it's not like there are, hidden pitfalls beyond what we are talking about here that I can, can say. the, you know, those are the kind of key things to get right, and if you have that right, I think you're in a very good place because it allows you to be relatively flexible with where you store, store things. And how you manage the entire setup. I think it's a, it's a good step forward."
    },
    {
      "speaker": "stephan",
      "time": "20:52",
      "start": 1251.64,
      "text": "Yeah, and I think there's a few things I wanna dig into here, but I think one point that is worthwhile pointing out is that multi-signature with different devices, device types, also helps you versus what's known as the chosen nonce attack, whereas many devices in a single-signature context, even with a passphrase, aren't safe, partic- aren't necessarily safe against the chosen nonce attack. Now, I think it gets a bit complicated here. Because there are some devices, so for example, off the top of my head, I believe BitBox o two and the Blockstream Jade have this anti-XPhill or anti-klepto protocol, which is there to help you against that. But there are all kinds of trade-offs with that too, because that-- those devices, you get the anti-XPhill when you are using USB, you don't get that when you're using QR code. So I think that's another reason to think about multi-signature as opposed to just single signature and a passphrase, because it's possible that you, I mean, it's kind of theoretical risk, but it, you know, it could be a thing if, you know, the value of Bitcoin got big enough and you were unknowingly purchasing a wallet that had been compromised by maybe somebody in the factory where those wallets are made or the devices are made, as an example. Whereas if you have multi-signature with multiple device types, now you're just so much more protected against that, right? so I think that's an interesting point that people have to just consider that passphrases can help you against some types Attacks, but they don't help you against everything that multisig can help you against."
    },
    {
      "speaker": "craig_raw",
      "time": "22:20",
      "start": 1339.9,
      "text": "Yeah, I mean, I, I think that the chosen nonce attack, you know, the, the best way that I would, you know, protect myself against that is, is, you know, upgrade your firmware to the most recent version when you have your new device, you know, that, that way you can kind of, you know, do at least some degree of, it's, it's not a sort of a perfect answer, but I think it does certainly ensure that, At least you're doing that degree of check, because when you upgrade the firm- firmware, the device should have to check it, and while that check, you're still to some extent trusting the device to do it, you at least can also check, and you can check, yes, the download that I have made matches the fingerprint on the site. So that I, I think, think is a good sort of approach. You know, in terms of all of the devices now, they should be creating the same signatures as Bitcoin Core or Sparrow. So, you know, there's a sort of, RFC which details how you choose the nonce, the specific approach, and everyone should be following that approach. And if you follow that approach, then the actual signature bytes are the same. And I've kind of gone through a process with many of the ven-vendors to make sure that they are actually doing this. So, you know, we, we have, signatures which are not, not only looking the same, but also of the smallest size, which is obviously important if we want We want to keep our fees, fees low. So there is, as I say, a, a, a s-a sort of approach which allows us to then choose the nonce and if it ends up with a larger signa-signature size because the nonce is just a random thing, then you can then go on and choose the next nonce, right? And then that allows you to then see, okay, the signature that I now get out is smaller than the one that I got before, and therefore I'm gonna use that one. So that's, is called, grinding for low R. It's the, the upshot of all of this is that if all of these devices are literally creating the same bytes, then obviously we can say that unless everything is compromised, we can be reasonably sure that we're not leaking additional information in that function."
    },
    {
      "speaker": "stephan",
      "time": "24:33",
      "start": 1473.35,
      "text": "one other area that I think would be great if you could help clear up, I commonly run into this and I often explain this for people, but it would be great to hear you explain it for people as well. So if you could explain the difference between these concepts, right? So I'm just gonna list them out. So we're You have your seed, you know, like you can think of it like your twelve or twenty-four words are a representation of that. You have the passphrase, you might have a PIN on the device, and then fourthly, you might have a Sparrow password. So could you just help explain the difference between those four concepts just for listeners who are a little bit, newer or using this opportunity to learn?"
    },
    {
      "speaker": "craig_raw",
      "time": "25:07",
      "start": 1506.55,
      "text": "Sure. So I, I think one can think of the Sparrow wallet password and the PIN on the device as very much the same kind of, kind of thing. They control access to the device Or to your Sparrow wallet. They are basically just a gatekeeper in front of things which allow you-- they don't change in any way, what's going on inside the wallet or inside the device, they just allow you to access it at all. Otherwise, you just simply, you can't get in. Then in terms of the passphrase, that's actually like an additional word added onto the end of your seed words, and that changes your entire seed. So that's why when we were saying earlier, it creates Creates a, a completely different and valid wallet. That's, you know, the effect of the passphrase is really to be able to add this, this additional thing which creates a wallet that only you kind of know about. And the big advantage of that, is that you are then able to ensure that even should your Sparrow Wallet password be found, or indeed your device PIN, that passphrase, given the fact that it's a- Different thing, somebody would have to enter in a pass, passphrase, and then go and check the blockchain to see whether there are any funds for that particular wallet that they have now created. And if they don't, then they're gonna have to go and try the next one, and, and that's a very much slower process than trying to guess, for example, your Sparrow wallet password. Now, even that is slow because Sparrow uses, a relatively slow key derivation algorithm by choice in order to make it More difficult to attack. But the passphrase thing is, you know, you're going to a blockchain, which is a very large database, and you're trying to look things, things up, and you can imagine that's never gonna be very, very quick. So we're just trying to put things in which not only hide the wallet, but also make it much more difficult to brute force."
    },
    {
      "speaker": "stephan",
      "time": "27:06",
      "start": 1625.75,
      "text": "Back to the show in a moment. When it comes to securing your Bitcoin, think about the hardware you use. CoinKite dot com makes some awesome Bitcoin hardware and accessories for your Bitcoin, most notably the Coldcard Mark IV. This is an extremely versatile and reliable device. You can use it to spin up your Bitcoin wallet totally offline. All you have to do is plug it into the wall or use the cold power, and you can charge your device in that way, and you can use a micro SD card to move things back and forth between your computer or otherwise. You can also use it with NFC, you can use it in various configurations, whether that's single signature or multi-signature. So to get your coldcard and your associated gear, go to coincard dot com and get a discount on your coldcard with the code LIVERA. Built on L2 is a community for builders by Blockstream. This is a community led effort with contributors and companies who are building on core Lightning and the Liquid network. So it's an interactive community, whether you are a builder, a product manager, designer, an engineer, or just simply an interested- The onlooker, you can join. There are mentorship programs to fast-track your success. There's a community space where you can ask questions and discuss with other bitcoiners and build the future of Bitcoin Layer 2. Go and sign up. You can get access on the platform over at build on l2 dot com. And finally, Unchained dot com. Unchained Capital can help you by improving your security to multi-signature. Unchained Capital is secure, transparent, easy to use, and sovereign. In most setups, you have two keys which you keep in different locations and they hold Hold a third key. They can walk you through the process of setting it up, or you can go and set it up yourself on the website. If you pay upfront for the concierge onboarding program, they'll ship you some hardware, they'll teach you how to use it, and you can then increase that security and give yourself that additional peace of mind by removing single points of failure. Unchained are also thinking about that inheritance scenario, so you can give your executor one key from a two of three vault. There are step-by-step checklists, there are letters for the executor or trustee, and other Go to unchained dot com slash concierge, use code livera for a discount there. And now back to the show. I see. Yeah, and I think it's an important thing just for people to understand the difference, to understand those four concepts, because if you misapply that, you can get things wrong, and if you mi-- if you confuse things. So for example, if, if a listener's out there, maybe they're a little bit newer, and they confuse the passphrase with, say, the Sparrow application level password, they're totally different things, and it will show you"
    },
    {
      "speaker": "stephan",
      "time": "29:35",
      "start": 1775.47,
      "text": "Different addresses, and of course, this is partly what the life hash, which is the new feature you mentioned, that's helping-- I guess that's there to help them decide or determine, \"Am I looking at the correct wallet?\" But it, it's just useful to have a conceptual awareness of these concepts so that way we can be more Secure and make the right choices when we are deciding how to secure our coins and all of this, right? Yeah,"
    },
    {
      "speaker": "craig_raw",
      "time": "29:58",
      "start": 1798.15,
      "text": "yeah, agreed. You know, it's, it's, I, I think the adding that life, life hash thing was, for me, you know, they're just trying to avoid the support requests that come in when people have had a typo or, you know, that's, I think the, the key, key thing. So I'm gonna keep on trying to work at that, hopefully we'll eventually get, get to a point where people That they enter rather than just, you know, going for it."
    },
    {
      "speaker": "stephan",
      "time": "30:25",
      "start": 1824.95,
      "text": "Yeah, and let's chat a little bit about NFC support. I know this is something that is, available in the TapSigner, it's available in the MK4, some other devices are out there. I know this is something you have also added support relatively recently as well. What's that, what's that been like? And are people using it a lot or not really?"
    },
    {
      "speaker": "craig_raw",
      "time": "30:43",
      "start": 1843.09,
      "text": "You know, I, I was really unsure of how much use it would get, and I've only had a few weeks now to judge it, but I, I, it's certainly being used, I'm certainly getting queries and people are talking about it, so, you know, it's, it's-- I, I would say that it's got more use in the last few weeks than I thought it would, which I think talks to the success of the product itself. And I think, you know, you kind of have to ask at the price point of buying"
    },
    {
      "speaker": "craig_raw",
      "time": "31:13",
      "start": 1872.79,
      "text": "Because, you know, generally your computer doesn't have a card reader in it, plus the, the card, card itself, you know, you're kind of, for one card, you're kind of already looking at what, for example, a cold card would cost. So, you, you, you, you got to ask why would you do it? And, and my answer to that is that there are setups, for example, multi-signature setups, but also, I think one that's interesting is, say you have, you know, a few kids and you want to introduce them to How to self custody, getting them all to buy, you know, buying them all a seed, a sort of, sorry, a cold card might be quite an expensive thing, and there's a lot of com-complexity in using it, but the TapSigner is just a single card and you put it on the re-reader and enter in a short PIN, and then you have full use of it to import, to sign, all of those kind of things, and for me, that's a nice way to be able to get people in, just from my own point of view, it's Quickly risen to be a common way that I will test things if I'm testing, for example, a multi-sig or what have, have you, I will generally tend to use that just because it's so easy to use. You're not trying to enter a PIN and then get this thing to work or do some kind of an egg, sort of egg act thing, you know, you just have a very easy system. So it's kind of ease of use is high, and I would say that when, once you've started buying more than one, the price point really does start"
    },
    {
      "speaker": "stephan",
      "time": "32:43",
      "start": 1962.69,
      "text": "It could make sense, maybe in a business context, like let's say a bunch of people have, you know, these tap signers and maybe it's like a multi-sig, so it's not just a single signature wallet, but maybe a few people, like let's say five people get together and they have a three of five, and each of them has a tap signer or whatever, they've each got their own device, maybe it makes sense from that context, for the larger spending, let's say, so it kind of remains to be seen,"
    },
    {
      "speaker": "stephan",
      "time": "33:11",
      "start": 1991.39,
      "text": "what's Back and forth with NFC rather than, doing it all with, you know, card and, you know, these little SD cards in and out all the time, but, still, a useful feature. So let's see what happens there. In terms of, I guess, multi-sig adoption, do you see that there's much-- I guess just broadly looking at the user experience for multi-signature, I mean, I think most people can agree it's a massive security improvement. It's probably an improvement in redundancy so long as you've done it correctly. Do you foresee more Multi-sig and in terms of the average, just Bitcoiner, like just the, you know, just an average guy who's got a Bitcoin stack, let's say over the years as the cycles go on, do you see that as mainstreaming and normalizing, or do you see them sort of staying in single signature? Do you have any predictions?"
    },
    {
      "speaker": "craig_raw",
      "time": "33:59",
      "start": 2039.28,
      "text": "That's a hard, hard one to predict. You know, I think that, without wanting to get too deeply into it, because it's an area which, I still need to spend some time on myself, I think that if we Proposal come in, then, you know, that might really affect things, because that provides a security model which I think is would, would be very interesting to many. But I do think, you know, just zooming out, I do think that the, there is a general progression as more and more people become comfortable with how Bitcoin works, how self-custody works, how these different concepts like output descriptors, how they can be used, I think we are gonna see See multi-sig come to the fore, you know, it's really just about getting people used to the ideas of it, you know, I think that just a few years ago, we had a relatively difficult, you know, I remember trying to set up a multi-sig using Electrum wallet back in the days before I built Sparrow, and it was difficult, it wasn't easy for me to do, so things have now changed a lot, you know, we've got a lot more, more apps, we've got a lot easier import of being able to import Import the, the right way and, you know, the, the right kind of formats to get a multi-sig wallet going. And I think that the fears that you sometimes hear are generally maybe coming from the, that sort of earlier era where you had systems that were really just not well designed for it. You know, for me, I, I can't imagine how it could be much easier to set up a multi-sig wallet, you know, in Sparrow right, right now, it's, it's, it's, it's really not a difficult thing To do, and I would encourage anyone who thinks it is just to try it, you know, just give it a go, you know, by, you know, create a bunch of seed phrases and try and, and sort of get it set, set up and see how it goes, because it's really not a difficult thing. I suspect we will see more of it, as a result. So yes, I think multi-sig is coming."
    },
    {
      "speaker": "stephan",
      "time": "36:05",
      "start": 2165.14,
      "text": "Yeah, and I think OpVault may change things a little bit, and it could also be layered, layered together, right? You could even have multi signature and maybe depending on how things go, it may be common to people, for people to use OpVault in combination with multi-signature. So then it just makes it even harder that, let's say, you have your two of three or your three of five multi-signature and you've got an OpVault recovery pathway. So then if that becomes really mainstream and it's known that any serious hodler is using multi-- some combination of multi-signature and/or OpVault, it might really reduce the overall amount of theft. In a way, right? Like as my friend Michael Flaxman has mentioned, that we, we might be able to make it clear that multi-signature is such a common and easily used feature for anyone with a, with a lot of coin that it actually helps prove out this whole idea of Bitcoin as this uncensorable or difficult to seize money. And I, that to me, that's just a really cool idea, but it, of course, it remains to be seen where OpVault goes, if it comes or not, but I, I think it'd be a cool thing to see. Seeing it. Do you have any other thoughts on OpVault?"
    },
    {
      "speaker": "craig_raw",
      "time": "37:16",
      "start": 2236.45,
      "text": "Not hugely at this time, apart from the fact that I think it would be a very useful, you know, thing to add. I'm certainly not, saying we should add it fast or rush it in. I think it requires a lot of due care, but, I, I think that the idea is certainly good, and that's the, the general, you know, view that I have seen is that most people seem to regard the sort of idea behind it as good, and there are, I think On the way in which it's been implemented to date. The other thing about multi-sig that I would like to just say is, is you know, it, it is obviously, as you mentioned earlier, when you have multiple individuals involved, it is really useful for that, particularly in a business context. if a business wants to store funds, the immediate question is how do we do it? And multi-sig is the obvious answer because it allows multiple employees to then hold the keys and no- One of, one of them can then run off, and that kind of gives everyone a feeling of we're doing the right, right thing. So as I was saying earlier, the, the next version of the Sparrow is gonna have a standard in it, it's called, BSMS or BIP one two nine, and that is basically an import and export standard which allows people to share the different, you know, key stores or, or shards, if you will. you know, in their multi-signature setup, the, the different signers can then exchange over whatever secure channels they use, and then they can, one of, one of them can then, you know, take all of those different signers, compile them into a multi-sign wallet, and then share the multi-sign wallet as another file, also a BSMS file, and then everyone else can import that. So it kind of just gives you a mechanism to be able to conduct this remote- Multi-sig setup in an easy way."
    },
    {
      "speaker": "stephan",
      "time": "39:12",
      "start": 2351.57,
      "text": "Yeah, so just to be clear, today, you could have the same Sparrow Wallet database file, right, that dot mv dot m dot db file, let's say you, me, and a third person, we could share that database file today and share, let's say we had a Signal chat, let's say you, me, and this third person had a Signal chat, and we could share our PSBT through that, and one of us could just kind of do that coordination role and do it that way, but I, I presume BSMs would A way to do that, maybe across wallets, is that, is that the goal here or what, what's the goal?"
    },
    {
      "speaker": "craig_raw",
      "time": "39:44",
      "start": 2383.71,
      "text": "Yeah, so I mean, it must be said that this first implementation, you know, there's a lot, lot to BSMs which, really, you know, to get the full benefits requires integration with the hardware devices themselves, because the idea is that every single signer signs their own information before they send it out, and then when the information is all compiled and brought to- Together, it includes the first address of the wallet, and then the idea is that, that first add-address is then the, the device then goes and checks, okay, A, I am a signer in the quorum, and B, the first address of this wallet matches the one that I think it should, should, should be. Now, unfortunately, we're just not there today in terms of vendor support. It, it's, it's one of those difficult things where it requires a lot of people to kind of work in concert to deliver a UX experience. So this first- Implementation that I have been working on is really just the basics of being able to share the information back and back and forth. And, and for many people who don't necessarily want to, you know, you can't, for example, at this point, save a invalid wallet file, in Sparrow Wallet, it kind of, it prevents you from doing that. So what you, you should do is then everyone then imports their own device in, whatever that is, whether it's a soft-software wallet, hardware wallet, whatever it is. And then they export this B S M S file, they share it, and then everyone can import those. So it's just a, a, a means at this, at this early stage of being able to share that information out. Otherwise, you'd have to send around xpubs and the, and, you know, the sort of other details, which is, less of a, of a convenience. So I, I think it's really, just making it easier to do those remote multi-sign setups."
    },
    {
      "speaker": "stephan",
      "time": "41:34",
      "start": 2493.72,
      "text": "I"
    },
    {
      "speaker": "craig_raw",
      "time": "41:34",
      "start": 2493.8,
      "text": "see,"
    },
    {
      "speaker": "stephan",
      "time": "41:34",
      "start": 2494.04,
      "text": "yeah. So I guess today it's possible, even now, Technical competence and a little bit more manual jiggling with the system, let's say, as opposed to the hypothetical BSMs future, is, I guess, one way to explain that, right?"
    },
    {
      "speaker": "craig_raw",
      "time": "41:50",
      "start": 2510.03,
      "text": "Yeah, yeah. I, I think, you know, we, the, the, the idea here is to kind of solve the need of people who just want to set up a remote multi-sign now and kind of make that particular task easier. But in time, I hope that we'll see vendor support as well, which will just allow all the kind of verification angles of it To come into play. So, you know, it's, as with most of these things, it's a road that we walk, walk on and, you know, we gradually get to the end, end goal."
    },
    {
      "speaker": "stephan",
      "time": "42:20",
      "start": 2539.61,
      "text": "And so let's also chat about your BIP three two nine. So this is related to the import and export of transactions. So can you tell us a little bit about that, how it came about and how that's progressing?"
    },
    {
      "speaker": "craig_raw",
      "time": "42:31",
      "start": 2551.2,
      "text": "Sure. So, you know, what we have, eve-everyone kind of, heard of, of, of the, the kind of common staff standards around seed words, for example, bit thirty-nine is what it's called, and that kind of defines how those seed words look and how, how they work, and that allows us to transfer our funds from almost any wallet on the market to a different wallet, and that's a really useful thing, you know, being able to not be locked into a particular wallet is an immensely powerful thing that we all kind of enjoy. Now Now, what we don't have is the ability to transfer the labels in one wallet to a different one, that is until bit three two nine came, came about. So the idea here is that you don't want to have application lock-in for any data that sits within that particular wallet. And what bit three two nine is, it allows you to export all of the labels from your wallet, and then for any supporting wallet, you can then import that file, and then essentially all of your labels will then be brought across. So It's a, it's a, it's a means to be able to do that, and as, as we know, labels are really important because we have this UTXO model, which means that, you know, all of your privacy is linked to whatever the UTXO came from. So being able to label it gives us a hint of, okay, well, I spent this before, it was the change output from a transaction there, so if I spend it to someone else, they're going to be able to follow that back, and it just allows us to be more private when we can label And what that trail looks like. So I think labels are important, labels should be used, and we shouldn't be locked into any particular application, and that's really what the ex-- the sort of import and ex-export of them is all about."
    },
    {
      "speaker": "stephan",
      "time": "44:16",
      "start": 2655.71,
      "text": "So yeah, that could be handy for people who need to just keep records as well, like of what did I do, what was this, what does this transaction relate to, and being able to, you know, easily move that across wallets or export it out into other applications even just for- Assessment or accounting or other purposes. Also wanted to chat about the privacy aspect of it. I know there's been a lot of discussion, it's ongoing discussion about bit forty-seven, pay-n-ems, or, you know, just this idea of having a payment channel, but it's like an on-chain payment. And so I think there are some debates online about whether that should be used or adopted. We are seeing, I saw recently there was some news about a new wallet called Stack Wallet who has it. So, so Samurai Wallet has it first, obviously. The Sparrow Wallet has it. There is some chatter about some other wallets adding it, but at the same time, there are, there are people critiquing the idea. So why is Bit 47 important or good from your perspective, just, for people to understand?"
    },
    {
      "speaker": "craig_raw",
      "time": "45:14",
      "start": 2713.7,
      "text": "Sure. So I mean, I think the, the, the key, you know, thing that it gives you is, you know, how can I in a non-interactive way receive payment from someone else, right? And when I say non-interactive, I mean I'm not going to be talking to them Me funds, and I don't have to speak to them or do anything on my, my part. And there's a number of ways that you can do that today. Number one, you can put a Bitcoin address out there in the world, still a very highly used approach. It has the huge downside is that the entire world can see ex-exactly how much money I have got on that address, right? That's completely open. So that is a very big disadvantage to that, that. And if I want to spend those funds, everyone can see that as well. So that's generally not the best route. The second kind of approach is to run something like BTC Pay server, which allows a new address to be sent, but of course that, that requires you to run a server, and for many people in the world, that isn't an easy thing. You know, you now have to set up a server somewhere, you have to keep it going, and then that server can then generate new addresses as required. So bit forty seven is a different approach, if you can say, kind of a third approach, which allows you to put out this thing called a payment code. It's a really long series of letters and num-numbers, and any bit forty seven compatible wallet can take that payment code and can then construct an address which that payment code, and only that payment code, can see. And that's a really pow-powerful thing. It's, it's, it's kind of allowing people to-- You could create a banner, a placard, for example, with a payment code on it And anybody around the world can send you money to that, and if that, that's a powerful idea, I think, you know, it's an idea that one can have this static address that anybody can send to, and that sending is then private. that's generally the-- that's, I think, the, the key kind of idea that Bit forty-seven is trying to solve. Now we have a number of other competing approaches which have come about in the last sort of year or so. We've got Silent Payments, and then another one called, I think it's Bit three five one Private Payments, and that one, both of those are doing the same thing as what Bit forty-seven is. They try to improve on it in certain, certain ways, which we can get into, but I think Bit forty-seven ultimately for me is Still the key one because it has this ability to be used and integrated with all wallets, whereas some of the others require full nodes, which is not some-something. Again, you know, if you can run a full node, maybe you can run a server anyway, in which case you might as well be using BTC Pay Server. So for me, it's, it's, it's really, you know, I haven't seen anything that rivals Bit 47, and it's not a perfect, spec, I, I would say that it has Downsides for sure, but I think that the utility that it has is really unmatched. Being able to run a light wallet client and receive funds from a static address anywhere in the world, I think is, is quite a unique feature."
    },
    {
      "speaker": "stephan",
      "time": "48:26",
      "start": 2905.59,
      "text": "Right. And so as you were saying, I think that's probably the key point that Bit47 solves for that some of the other approaches may not. And so in practice, I think it's more likely that Bit47 is going to stay, at least for- For the users who are focused on, on chain. Perhaps in the future, if more commerce shifts to Lightning, then maybe some of it moves to things like Lightning Address or maybe in the future Bolt twelve, LNURL, these kinds of approaches. but yeah, it seems to me like Bit forty seven is going to be the useful approach for, especially in the case where you need to regularly pay the same person again and again. So especially in the context of an employer relationship or even mining pools, I believe Lincoin has this feature as a mining pool, which is pretty cool. So maybe over time we sort of see a shift towards the Bolt twelve or Lightning address style, because maybe that's more scalable and u-usable for these smaller transactions. But I think the Bit forty seven, it seems to me like it's here to stay at least in certain niches. I think maybe the criticisms I could understand against Bit forty seven is one, there's not a lot of wallets who support it, right? And I think that's fair. And secondarily is the aspect of needing a notification transaction on chain for every individual that you wanna set up this Bit forty seven, let's call it a Bit forty seven channel or have that transaction notification. So I think that's the other aspect where I could understand if you wanna take donations, it's kind of, it's a lot more friction if you need somebody to be able to do that on chain notification and then take donations. Certainly it makes sense for large donations that people would do that, but I think in the context of, let's say, I- I need to just put this QR up and just take quick donations. I think maybe Bolt twelve or Lightning address style approaches are faster in that way, but certainly they come with their own trade-offs too,"
    },
    {
      "speaker": "craig_raw",
      "time": "50:20",
      "start": 3020.21,
      "text": "right? Yeah, I mean, the, the big downside is that of course, Lightning requires you to be online, right? You need a node, and either if you're gonna run your own, your own node, which you should of course, because we're all trying to be as non-custodial as we can, then that node needs to be online, stay online, in which case you're very The same situation as BTC Pay Server, which, you know, I've got no issue with, but, you know, it is a more difficult thing for many people in this world. I would actually say that, you know, I, I, I do note the, you know, that some p-people have an issue with sending this notification transaction. The cost of it is actually really small. It's like the minimum amount that you need to spend, like five hundred and something sat. So, I mean, from a, from a cost point of view, it's really- Minimal. I would say that the, the, the kind of the, the more impactful thing is the fact that you have to be a little bit aware of the UTXO that you use to send it, and Sparrow does some work to try and make sure that it doesn't, you know, re-spend UTXOs or at least the change from notification transactions unless it needs to. So I, I think that that's more of a concern than, you know, spending what is really a tiny amount of mon-money. The other, I think down-downside Is that you need to use a hot wallet, and for many people that isn't ideal. That said, I will say that, you know, there, there are many, many hot wallets in this world, and we hear remarkably few cases where those hot wallets are being compromised. you know, I'm, I'm sure it does happen, but the reality is most of the time you hear about people forgetting their passphrase, not about the fact that somehow their hot wallet was hacked. So I, I think that, you know, you know, those, those two aren't downsides, but they're not massive in my view, and certainly not a reason that people shouldn't be trying to, implement Bit 47 and trying to"
    },
    {
      "speaker": "stephan",
      "time": "52:19",
      "start": 3139.03,
      "text": "use it. Yeah, and I think one other aspect that if we want to see more Bitcoin use, and I think most of us agree with that, we want to see more people using Bitcoin and adopting Bitcoin. One thing that would be really useful there is having a feature, something like a contact list in our app. Applications. And I think maybe that's been one difficulty so far. I know some people have tried it, there have been attempts at this, but it just, it hasn't seemed to stick really, other than, let's say, in Samurai Wallet or perhaps in Sparrow Wallet if you have a few PayNems that you have already set up with or, Bitfortyseven codes that you've set up with. And I'm curious your thoughts there. How important or relevant is the, is this notion of a contact list in our Bitcoin wallet?"
    },
    {
      "speaker": "craig_raw",
      "time": "53:00",
      "start": 3179.53,
      "text": "Yeah, I mean, I, I do think Paynums have seen such adoption, really, you know, it, it is unusual for Bitcoiners to use a cent-centralized kind of service, and I don't think that it's going to stay, stay that way. I think it is due to change, and become a more decentralized thing, but Paynums certainly indicate to us how it's so much easier just to remember someone's NIM and then be able to enter that in, so, you know, it's useful, but, you know- Again, we want to be cautious here because we don't want to get tied to something which, you know, creates too many connections to a service that we might not be able to control. so, you know, I think some pros and cons, but I can certainly see how, you know, if you want to send a donation to Sparrow Wallet, you can just, you know, enter that in as a sort of Paynum and it pops up, so it makes life so much easier. Right."
    },
    {
      "speaker": "stephan",
      "time": "54:01",
      "start": 3240.55,
      "text": "and so when it comes to just Bitcoin more broadly, we've been talking About security and a little bit about privacy as well. I'm curious if you have any things on your wish list or things that you would like to see, kind of as a closing comment. Is there anything that you would, you know, if we could wave our magic wand or if, if you could see development go in a particular direction, what sorts of things would you like to see?"
    },
    {
      "speaker": "craig_raw",
      "time": "54:24",
      "start": 3264.05,
      "text": "Well, I mean, I, I guess my, you know, sort of perennial one is really splicing, cross input signature aggregation. that one is, you know, is just a, a particular approach to being able to have one signature for all of the inputs of a transaction, and the big advantage to that is not only that it makes transactions smaller and they're cost less, but I think the, the key one is that it changes the fee dynamics to favor transactions Where you have multiple, people coming in, and that of course breaks the common input ownership puristic. So for me, that is always gonna be top of my list, and I'm gonna be asking for it and wanting it, until hopefully one day we see it. So, you know, if there was ever, you know, I, I do believe that there's some work ongoing on it, but, I'm kind of unaware of how much and how far off it is, but that for me, it's always gonna, gonna be very high on the list."
    },
    {
      "speaker": "stephan",
      "time": "55:24",
      "start": 3324.27,
      "text": "Yeah, and in fact, I know, Jonas, Nick, and Tim Roofing were doing some work on half aggregation, which is a related idea. I've got an episode on that. But, in terms of the broader, the full piece, I think that's going to be some ways off. Of course, I would like to see that as well. I think it would be a big win for scalability and potentially for privacy also. So it'd be really cool if we see that. I'm hoping. Here's hoping, right? I'm hoping. Yeah, yeah, Well, listeners, make sure you follow Craig. Sparrowwallet dot com is the place to go to get Sparrow Wallet. Follow him, you can find his handle is craigraw and most places, and I've got the, I'll put the Nostra N Pub and a few other details in there. Craig, thanks for joining me and, great job with everything you're doing on Sparrow Wallet and, Bitcoin development."
    },
    {
      "speaker": "craig_raw",
      "time": "56:12",
      "start": 3372.4,
      "text": "Thank you, Stephane. It's been great to be here again. yeah, it's, looking forward to the next, We'll be able to get out to a few conferences this year, so yeah, I'm looking forward to seeing, seeing you."
    },
    {
      "speaker": "stephan",
      "time": "56:30",
      "start": 3389.8,
      "text": "Get the show notes over at stephanilivera dot com slash four six two. Thanks for listening, and I'll see you in the citadels."
    }
  ]
}
