{
  "episodeId": "SLP476",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "nick_farrow": {
      "name": "Nick Farrow",
      "role": "guest",
      "tag": "NICK"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:08",
      "start": 8.37,
      "text": "Hi, you're listening to Stephan Livera podcast, a show about Bitcoin and Austrian economics brought to you by Swan Bitcoin. Today, for episode four hundred and seventy-six, my guest is Nick Farrow. He's joining me to talk about Frost. What is it? What does it mean for Bitcoin multi-signature security? What kind of benefits does it have? What are some of the downsides? And what is Roast, as well as how does the hardware and software have to- Shift to adapt to this. This show is brought to you by Swan Bitcoin, and if you are a business owner and you are looking to add Bitcoin to your corporate balance sheet, it's never been easier. If you're seeing all of this that's going on now with banks failing, Swan Bitcoin Treasury Solutions makes it easy for you to incorporate Bitcoin into your financial strategy. You can automate your Bitcoin investment, custody, and management strategy, and you'll get expert guidance every step along the way. Also related is Swan's Bitcoin benefit plan, if you have staff and you'd like to be able to give them a- A fringe benefit of some Bitcoin every month, Bitcoin Benefit Plan makes it easy for you to recruit, reward, and retain top talent with Bitcoin. Swan handles all the heavy lifting like creating wallets, converting currency, routing payments, and like magic, your employees receive Bitcoin and a world-class financial education monthly as a benefit from you. Go to swan dot com slash business. When it comes to Bitcoin blockchain explorers, mempool dot space is the leading one. You can use it whenever you're about to send a large Bitcoin on-chain transaction so you know what kind of fee to transact with. And with mempool dot space, you can see the multi-layer ecosystem of Bitcoin. You can see the mempool, you can see the blockchain, you can see the lightning network, and so much more. With mempool dot space, you don't even have to trust a third party. It's free and open-source software, you can host it yourself. Now, for enterprises, mempool dot space offers customized mempool instances. You can get your company's branding, increased API limits, and more. So go learn more at mempool dot space slash enterprise. Now, when it comes to securing your Bitcoin,"
    },
    {
      "speaker": "stephan",
      "time": "02:00",
      "start": 120.02,
      "text": "array of Bitcoin security products and accessories, most notably the Coldcard. You can get the Coldcard Mark IV, it's out now, it has two secure elements, it has NFC support, it's really reliable, and you can spin up the device without even plugging it into a computer, and you don't have to phone home, which is a great benefit that you get when you're using the Coldcard. Of course, they have a new device coming out which you can pre-reserve, it's called the Q1. This new device will have a QR feature also, but the Coldcard doesn't Micro SD card, and of course, if you're a beginner, you can just directly plug it to your computer and use it easily with wallets such as Sparrow or Spectre. So go to coinkite dot com and get a discount on your cold cards with the code livera. On to the show with Nick."
    },
    {
      "speaker": "nick_farrow",
      "time": "02:44",
      "start": 164.15,
      "text": "Nick, welcome to the show. Thank you very much, Stefan. Very much looking forward to it."
    },
    {
      "speaker": "stephan",
      "time": "02:49",
      "start": 168.98,
      "text": "So Nick, I know you've been, you've been, working on a bunch of different things in the space, and, recently, a big focus in your work has been around all this stuff, and we're gonna break it down today, try to keep it accessible for everybody around Frost and Roast and MultiSig and Nostrum and what does it all mean, right? so, yeah, do you wanna just, I guess, give us a little"
    },
    {
      "speaker": "nick_farrow",
      "time": "03:14",
      "start": 194.39,
      "text": "Yeah, for sure. maybe I'll start with a bit of a funny story. I first met, ran into Stephan at a Bitcoin Bush Bash. I remember Beachworth."
    },
    {
      "speaker": "stephan",
      "time": "03:23",
      "start": 202.94,
      "text": "yeah, Beachworth,"
    },
    {
      "speaker": "nick_farrow",
      "time": "03:24",
      "start": 203.7,
      "text": "yeah, Beachworth. And that was my, that was my first sort of exposure to a, a Bitcoin event actually. And Wizard of Oz sort of convinced me, well, I, I sort of, I, I proposed the idea to him that I could present this payment processor, SatSale that I'd been tinkering with. And so I got up at, at Beachworth and and I, I think you sort of caught onto that, I was sort of talking a bit, a bit talking badly about other payment processes and, and talking up SatSail a bit, which is really just, you know, a really crappy HTML button that you just spit out addresses. but yeah, that was awesome to meet you there and, and, it was really good that I, decided to do that, 'cause that's how I met, the people I'm working with at the moment. So, yeah."
    },
    {
      "speaker": "nick_farrow",
      "time": "04:14",
      "start": 253.73,
      "text": "What I like to call the next generation of, of Bitcoin multisig, and it, it uses the, Taproot upgrade that Bitcoin had quite recently. And yeah, it's, it's a lot of really exciting user experience, in terms of multisig signatures coming along pretty soon."
    },
    {
      "speaker": "stephan",
      "time": "04:31",
      "start": 270.56,
      "text": "Fantastic. And so can you break some of this down for us, right? Like, so as, you know, multisig exists today, right? That, there's like, you know, I think it used to be op check multisig, and now it's op check sig. But what's the difference now with Frost and what kinds of, you know, oh, if you could just start with that, yeah?"
    },
    {
      "speaker": "nick_farrow",
      "time": "04:50",
      "start": 290.22,
      "text": "Absolutely, yeah. So, yeah, like you say, Stephan, we do have multisignatures in Bitcoin already. so you can think of multisignature like you need multiple keys in order to spend, some Bitcoin. and, and multisignatures are really helpful 'cause you can do, a threshold. So say you have three keys, you might need, two out of Have those three keys in order to spend, that Bitcoin, and, and this is all customizable, to whatever setup you like. So I, I like to think of script multisig, which is the Bitcoin, the multisigs we currently have in Bitcoin, a bit like n individual locks or, or a whole bunch of smaller locks comprising a, a much bigger lock, and you can, you can customize that threshold, so yeah, it could be a three of five or a, a five of eight or a two of three, whatever you really like Like, so that script multisig, think of it like, yeah, n smaller locks comprising a bigger lock. Frost, on the other hand, is just really just one lock, and instead of having multiple smaller locks comprising that one lock, you have, a key that is fragmented or shared amongst a group of people. and the cool thing about Frost is you can still have this, threshold, t of n, so yeah, three of five, five 8, whatever you like. but instead of running in, in Bitcoin script, Frost is entirely done through mathematics, and it gets its threshold nature from mathematics. So that's the, that's the big difference between, what we have at the moment, script multisig, or sometimes referred to as legacy multisig, and Frost, which is coming soon."
    },
    {
      "speaker": "stephan",
      "time": "06:36",
      "start": 396.27,
      "text": "Yeah. And so could you also spell out, is there any relation here with some of the multisig two stuff?"
    },
    {
      "speaker": "nick_farrow",
      "time": "06:44",
      "start": 404.24,
      "text": "So MuSig is, also uses Schnorr signatures, so tap- that've been enabled through the Bitcoin's Taproot upgrade. MuSig is specifically n of n, so two of two, three of three, five of five. You can't do, the threshold. Now, MuSig, because of this, MuSig is more applicable to things like Lightning channels, where you're only really doing a two of two, whereas Frost, because you can- Do this threshold thing, it's better for your own self custody or protecting Bitcoin in a, in an organization or a business."
    },
    {
      "speaker": "stephan",
      "time": "07:20",
      "start": 440.48,
      "text": "Gotcha. And so as I understand, with some of this, there are some benefits and some costs here, right? Or some downsides. So presumably one of them is around privacy, that we're trying to make multisig look just the same as single sig, as I understand, that's one of the benefits, right?"
    },
    {
      "speaker": "nick_farrow",
      "time": "07:39",
      "start": 459.25,
      "text": "Yeah, that's, that's probably my favorite one. Yeah, one of my favorite things about Frost is that you have this, because it's a single lock, it looks like a single signature spend on chain. So it looks identical to any other, single Taproot key spend, on chain. Any other pay-to-Taproot, output spend, a Frost transaction or a Frost, a transaction that's ma-signed using Frost can look the same. And that's in, that's in- Dark contrast to, to multisig as we have it today. Current multisig is actually has really terrible privacy. you can go on mempool dot space and, you know, click through, some transactions, you'll eventually run across a multi-signature, and that multi-signature, it'll tell you whether it's a three of five or a, a five of eight, whatever it is, because when, when you spend those UTXOs, you reveal the script to everyone, and everyone can just read, oh, how many keys there are. It was a really interesting article, I really, really found really-- this is like blew my mind when I first read this. Someone analyzed the, the withdrawal addresses for Bitmax And in twenty nineteen, when one of the BitMEX executives got arrested, they were able to using, like, comparing the timing of which keys were signing and which executives were in custody, this researcher was able to figure out, like, which executives were holding which keys to the multisig and when they were signing. And that, that's like extremely terrifying if you're running, you know, a billion dollar, exchange withdrawals daily. It's, pretty crazy."
    },
    {
      "speaker": "stephan",
      "time": "09:20",
      "start": 559.9,
      "text": "Yeah, fascinating. And so I guess as you're saying, this, in a frost context, then, you know, you could re-remove some of that. Now, I understand some of the downsides here with some of this stuff. Could it be that there's more interactivity required or there's more complexity? Can you explain some of that for us? Like, what are some of the downsides of using frost?"
    },
    {
      "speaker": "nick_farrow",
      "time": "09:43",
      "start": 582.6,
      "text": "Yeah, so, so one of them that's, a direct flow on from the, the improved privacy is that, frost alone has actually Worse accountability, so you can't sort of say, \"Oh, I know you signed and you signed,\" right? because it's, it's very private. so in some settings, we believe there are some, modifications you make to Frost to make it more accountable to those within the multisig while it's still appearing highly private, to outsiders. in terms of other, yeah, complexities with running Frost, because it is entirely this off-chain protocol done with mathematics, you have to-- there's a bit more communication involved. and so before Frost, there have been other threshold Schnorr signature schemes, but they would often take many, many rounds of communication. So say we wanted to do-- sign something together, we might have to send messages back and forth. You know, three or four times. And so, so Frost in its name is flexible round optimized Schnorr threshold signatures. There's a lot in there, but the, the round optimized, means that you can actually do Frost signing in a single round, with some conditions. So, so we have to, in Frost, you have to agree upon, a nonce to use, like with standard Schnorr signatures, we have to, every time we wanna sign, we wanna use It's a unique nonce, and with what we can do to make it round optimized is we can share a whole bunch of nonces up front, and then, every time we go to sign, we just sort of pick the next, next set of nonces in the list, and we're, we're already ready to go, ready to sign. so that, that's where the, the round optimized part comes from, is that we can, by, by pre-sharing these, these nonces up front, we can actually, smash out these signing rounds in a single round,"
    },
    {
      "speaker": "nick_farrow",
      "time": "11:41",
      "start": 700.88,
      "text": "If you're using something like a, a hardware wallet, so you don't wanna be ferrying around an SD card, from your computer to hardware wallet to hardware wallet, like you don't have to do that, that process like three times, right? Yeah, exactly, exactly, and maybe in, maybe in a particular order as well, so it's cool that with Frost, you can do single round, signing."
    },
    {
      "speaker": "stephan",
      "time": "12:03",
      "start": 723.04,
      "text": "I see, yeah. So, yeah, I think that was one of the main things that, was let's say a downside of when, Interactivity, it maybe wasn't the most practical choice for, let's say, a hodler who wants to use multisig to secure his coins, because then he's gonna have to go back and forth, and let's say one of the hardware devices is in a vault somewhere, one is in like a family member's home, and one is somewhere else, and, and you're gonna have to go to these locations, not just one time to each location, but multiple times to each location, and it just, it just blows up the complexity and the practicality of using it, which, where Lightning, because these are, our lightning nodes are already online, they're already talking to each other, those round, extra rounds aren't such a big deal, but in the hardware device context, it's very clunky. It's a whole"
    },
    {
      "speaker": "nick_farrow",
      "time": "12:52",
      "start": 771.97,
      "text": "lot worse, yeah. Or, or if you, even if you're in like a company or something, you know, you don't have to, the signing process to take up like an hour of your executive's time or something, that would, would be ridiculous. you just wanna be able to click, you know, click sign once and"
    },
    {
      "speaker": "stephan",
      "time": "13:08",
      "start": 787.54,
      "text": "it's Are you able to give us a rough overview?"
    },
    {
      "speaker": "nick_farrow",
      "time": "13:13",
      "start": 792.93,
      "text": "Yeah, let's, let's get into it. so, so Frost, its building block is sort of Shamir secret sharing. so if listeners are familiar with Shamir secret sharing, you essentially, you take a, a secret that you want to split up into a whole bunch of fragments. a-and the way you do this is you, you, you create a polynomial and, and the, the constant term or the, the y-intercept in that polynomial Is the secret that you want to share, and then you, you generate random other terms for, for the rest of the polynomials, your, your x term, my five x, and then like three x squared, and, and you, you add, you add all these polynomial terms, and, and then you, you, you end up with this sort of random polynomial with your, your secret is the, the constant term, and once you have this polynomial, then you can start evaluating it at different positions like x equals one, x equals two, x equals three, and so on. And your choice of the degree of the polynomial, so how-- whether it's x squared or x to the five, this determines how many points you need To recover that initial secret. And, and the way I like to think about this is, if you have, say, two dots on a, on a piece of paper, just two random dots, there's only one unique line you can draw between these two dots, and, and that, that line, where that line intersects, the, the y-intercept would be your joint secret. Now, if you have three dots, you can draw a unique, quadratic between these These three dots, and again, the, the y-intercept would be your, your joint secret. So that, that should mean secret sharing. I hope I've done an okay job of explaining that one. Essentially, you take a, a joint secret and you, you split it up into a whole b-bunch of different points, and in order to reconstruct that, that joint secret, you need to have, some threshold number of points. so that, that's sort of the foundation of Frost. But, but what- One problem with Shamir's Secret Sharing is that, say you, you take a, a Bitcoin seed phrase and you Shamir Secret Share it into a, a whole bunch of, different points. One problem with Shamir's Secret Sharing is that if every time you want to use that seed phrase, you have to fully reconstruct it. so it's not like you can, you can sign with each individual, fragment of, of the Shamir shared phrase. Yeah. You have to fully reconstruct it And then that, that's where the, it gets risky, right? You've got your fra-- in one place again."
    },
    {
      "speaker": "stephan",
      "time": "16:06",
      "start": 966.08,
      "text": "Right. Because you're vulnerable in that moment, right? So if we compare to, let's say, multisig, and this is actually a reason why I think multisig is more practical for most people than Shamir's Secret Sharing, because in a multisig context, you can have, let's say, your cold card, you can be taking the PSBT and signing in that location with just one hardware device, whereas in the Shamir's Secret Sharing context, you"
    },
    {
      "speaker": "stephan",
      "time": "16:31",
      "start": 990.54,
      "text": "So if the criminal kind of comes to you, then you're in trouble at that point, whereas in a multi-sig context, you could have the devices in different locations such that at no given point in time you are fully just vulnerable to a criminal coming and saying, \"Hey, sign your keys over to me, sign your coins over to me,\" sort of thing."
    },
    {
      "speaker": "nick_farrow",
      "time": "16:49",
      "start": 1009.29,
      "text": "Yeah, exactly right. and, and so Frost, Frost gets rid of this, this problem, which is really awesome. I won't go too far into the Frost key generation, but, but just to give Idea. So to each party who wants to create a frost, a frost key, who wants to be a part of the frost multisig, we each create our own, polynomial, and essentially we, we add some combination of these polynomials together to have a, a joint polynomial, much like Shamir's secret sharing. And the, the really cool thing about this is that we, by doing so, we've essentially got this, joint secret to a polynomial that none of us in the multisig know But together we have enough i-information to recover it. And now we don't actually want to ever recover this, this joint secret, because like you said, we don't wanna re-reconstruct it and bring it back to one place or, or one device. So what Frost allows us to do is, it, Frost allows us to evaluate, that polynomial, so we can sign using it without actually having to, to reconstruct the secret. and so, so the way you do this is because each individual has their own, polynomial, they can sign with this individual polynomial, I sign with my polynomial, you sign with your polynomial, and what's really the, just the, the, the constant term of the polynomial, and then we add these combination, a combination of these partial signatures together, and we actually, result in a, a se- signature that is valid for the, the joint polynomial. So we each sign with our own little pieces, our own fragments of the key, and we're able to sign under sort of this, this group, public key. so that, that, that's the power of Frost, is that you don't have to actually reconstruct the secret itself. We can sign with, fragments of the s-secret and then combine it at the end, and we have this, a signature that's valid under the, the joint secret. I see."
    },
    {
      "speaker": "stephan",
      "time": "19:11",
      "start": 1151.27,
      "text": "And so as I understand then, it's just, let's say there's more complexity at the initial setup, right? Let's say you, me, and one other person, then we do a two of three, and we wanna do Frost multisig, there's just that initial, let's say, sharing of those, you mentioned the nounces, because that's what we're gonna use when we sign, not just the first time, but the second time, the third time, the fourth time, et cetera. That's the main extra complexity as I'm getting, as I'm understanding you."
    },
    {
      "speaker": "nick_farrow",
      "time": "19:37",
      "start": 1177.46,
      "text": "Yeah, yeah, that, that's right. So, yeah, that, that's really it. So key generation is, is two rounds, so we, to create a frost multi-signature is"
    },
    {
      "speaker": "nick_farrow",
      "time": "19:52",
      "start": 1191.55,
      "text": "Polynomial of our own, and then we, we evaluate, other people's, each other's polynomials at different points, and then, we get each per-person results with a single point on a joint polynomial. And then with signing, yes, i's, i's so-- it's usually two rounds, but you can optimize it to be one if you can decide upon which nonce's and which, parties are going to- Going to be signing ahead of time."
    },
    {
      "speaker": "stephan",
      "time": "20:23",
      "start": 1223.41,
      "text": "I see. And so as, as I'm understanding you, it's like you're saying, okay, this is early days, but let's say in the future, at some point, this kind of tech could be brought into the likes of Electrum, Specter, Sparrow, Nunchuk, Keeper, these kinds of multi-sig coordinator wallets, and this might just be another way to coordinate your multi-sig and actually use your multi-sig. Is that kind of how I'm understanding?"
    },
    {
      "speaker": "nick_farrow",
      "time": "20:47",
      "start": 1247.07,
      "text": "Yeah, absolutely. And i- it's great that you bring Something we're actually gonna be looking to, to work with is, is these, there's already so many great wallets out there, we don't want to be building, you know, a Frost wallet from scratch, is not, not something we want to be doing. So we, we would really like to, yeah, integrate with this with wallets such as YesFaro, Nunchak, yeah, that would, that would be the dream. And then, yeah, you're able to- create Frost keys across multiple devices and, and you can, you can sign across multiple devices, very similar signing experience to a, your existing script multisig. I"
    },
    {
      "speaker": "stephan",
      "time": "21:28",
      "start": 1288.34,
      "text": "see. And so when it comes to the coordinator, so as an example, let's just take Sparrow Wallet as an example, right? It's a very common coordinator software, let's call it. So are there any big wholesale changes required there, or is it more just like, \"This would- be another option to use inside these coordinating apps."
    },
    {
      "speaker": "nick_farrow",
      "time": "21:48",
      "start": 1307.9,
      "text": "That's a good question. There's, it's mostly communication, so it's mostly s-what kinds of messages are sent between Frost keys, or Frost devices. So yeah, you, you have this coordinator, say it's Sparrow, we'll have to program InterSparrow all these different types of Frost messages and, and how to, send, send this data back and forth between, Participants. Definitely, keeping track of nonces will be a, a very important thing as well, because you'll have to make-- it's, it's vital, like with regular Schnorr signatures, that you never re-reuse a nonce. if you reuse a nonce, you leak your secret, and, and that's exactly the same with Frost. So, so it'd be very important that these, these wallets have a, quite an intelligent, way of choosing which non- what nonce to use next for the next signing round."
    },
    {
      "speaker": "stephan",
      "time": "22:45",
      "start": 1364.82,
      "text": "I see. So I think probably I'm, I'm thinking of Nunchuck, where they have, let's say, a bit of an interface for chatting with your multisig counterparties or, you know, fellow, multisig people in that same quorum. And so I, I guess what we're talking about here is the coordinator app has to be smart, cor- smart enough to talk with the other users to say, okay, here are the nuances, don't use this one, use this one, that kind of thing, right? Or it has to be smart enough to help coordinate this setup, right? Because today, we could, as an example, with Sparrow or Specter or something like this, I could say, hey Nick, give me your xPub for your multi-- give me your multisig xPub, and I'm gonna, you know, I'm gonna generate a multisig quorum on my computer, and let's say we get a third person"
    },
    {
      "speaker": "stephan",
      "time": "23:34",
      "start": 1413.61,
      "text": "And Katán, give me a multisig xPub, I'll create it here, and then I'll export that, the, you know, the register your multisig quorum file back to you. That's kind of how it would work in today's, let's call it legacy or script multisig. But in a Frost context, that might need some more, you know, what is it, middleware or some way for these- Pieces of software to talk to each other and kind of share that information that's needed, right?"
    },
    {
      "speaker": "nick_farrow",
      "time": "23:58",
      "start": 1438.22,
      "text": "Yeah, absolutely. So yeah, that, that's a really good point is that, yeah, this frost key generation, it involves the sharing of polynomials and, and evaluations of these polynomials, it will need its own sort of, specification for how to sort of share these, this stuff and these messages so that each wallet, can hopefully understand the, the right types of formats and things. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "24:22",
      "start": 1461.76,
      "text": "And then let's say I've got nuncha- And you've got Sparrow and Katana's got Spectre, you know, they, they would still need to all be able to, you know, correctly speak to each other, right? Because I guess that's the other big trade-off, right? Because we were talking about this, but I think put it this way, legacy multisig is non-interactive in its setup. Well, mostly. Whereas this is, let's say it's interactive in the initial setup step. Yes. And I guess does that also mean we have to be really careful about not leaking these nounce, right? Like you'd wanna keep them offline."
    },
    {
      "speaker": "nick_farrow",
      "time": "24:53",
      "start": 1492.59,
      "text": "You want to keep the sec-- the nonce secret private, yeah, the, the one that you're, you're signing with for sure. I think I might've mentioned before, but the devices themselves or the users themselves should also have, software barriers to prevent nonce reuse. So we shouldn't also, we don't, we shouldn't rely on the coordinator to tell us, you know, use these nonces. We also want the devices themselves to, to reject, say, \"I've already signed with that, get lost, come back asking with a new nonce that I haven't used.\" Yeah,"
    },
    {
      "speaker": "stephan",
      "time": "25:24",
      "start": 1524.35,
      "text": "that's a good point, because, I remember, Stephan Sniegirev, who was a early contributor with Spectre, wrote and spoke about this kind of idea of how could I make a multisig or make a setup that works even if my coordinator Relying on the hardware device being able to correctly understand, as an example, \"Oh, this change address belongs to me, \"or \"No, it doesn't, it's a malicious change address, it's a change attack, right? \" That kind of... Now over the years, the multisig technology and hardware have evolved and, you know, improved to that level, and now there are techniques and things being done like registering your multisig quorum instead of being stateless and not understanding that, so that's, that's a quick example, but this is like a whole not just into the coordinator software, but also into our hardware devices. So, do you wanna just tell us a little bit about what, about what that would look like as a, you know, a Frost hardware signing device?"
    },
    {
      "speaker": "nick_farrow",
      "time": "26:21",
      "start": 1581.25,
      "text": "Yeah, yeah, absolutely. Just, one thing on the, on the xPub's, like, you raised a really good point about, Fro-Frost being more interactive, and require-- because like with no-script multisig, you just need to write like sort of a list of xPubs. One downside to that Is that if you, you can't lose any of those xpubs, and, and this was something that sort of really blew my mind, when I first heard about this, I was like, \"That can't be true, is that, is that real?\" But, in order to spend from a script multisig, you need to know every single xpub so that you can recreate the redeem script and actually unlock that UTXO, whereas with Frost, this, this won't be an issue. So that, that's, sort of a nice, a nice feature of"
    },
    {
      "speaker": "stephan",
      "time": "27:08",
      "start": 1628.4,
      "text": "This way, in multisig today or legacy multisig or script multisig today, it's very important that you keep a backup of the output descriptor, and that's something I often talk about, I'm saying, hey, make sure you keep that output descriptor backup, keep it in multiple places, you know, because you need that in, in a multisig context, right? It's not like in single signature, you're in another world now, you need to think about that piece. it, multisig is better, but th-the, this is one piece of additional complexity. So in a"
    },
    {
      "speaker": "nick_farrow",
      "time": "27:38",
      "start": 1658.44,
      "text": "Pub and then you can backup each, each, secret share. Right. So"
    },
    {
      "speaker": "stephan",
      "time": "27:42",
      "start": 1662.04,
      "text": "in this example, each user would have his own, let's say, metal seed backup for his, you know, cold card or whatever device you're using, right?"
    },
    {
      "speaker": "nick_farrow",
      "time": "27:48",
      "start": 1668.27,
      "text": "Yeah, exactly. backups is an interesting one. We'll, let's get back to, let's get into that in a little bit. so, so hardware devices. so yeah, hardware devices is something that we're actually experimenting with at the moment. And the way we, when I say we, this is Lloyd F"
    },
    {
      "speaker": "nick_farrow",
      "time": "28:09",
      "start": 1689.1,
      "text": "The way we envision these Frost hardware devices working is that, so you have your coordinator, so it might be Sparrow on a laptop, and then, you'd have a, a Frost hardware device, and you would, you would plug that, Frost hardware device into your laptop, and then you'd get a second Frost device and plug that into the first Frost device, and you sort of make this chain of, of Frost devices, all connected one into each other, so you- You say you wanna do a three, three of five. to do keygen, you could plug all five devices into sort of the backs of one another in this daisy chain. and then you, you get the laptop to, to say, \"Let's do keygen.\" The laptop sends a message down the chain of devices, and on each device, you can verify that it has the same view, of all the other devices. And once you, you look at each device, you check they all look the same, you, you go- down the line, sort of clicking a, an OK button and, and then you've got a Frost key. From then on, you can, you can unplug all the devices and, and geographically distribute them or, you know, give one to each, say, member of your, your business or company. Then whenever you want to sign, from then on, you can sign with one device at a time. So you could have your, your laptop coordinator again, plug one device in, sign, unplug that device, plug a second device in. In sign until you do a, you're three out of five. You could also plug a threshold number of devices into one another again and sign all at once, but that, that sort of kind of"
    },
    {
      "speaker": "stephan",
      "time": "29:50",
      "start": 1790.41,
      "text": "defeats the purpose. Yeah, it"
    },
    {
      "speaker": "nick_farrow",
      "time": "29:51",
      "start": 1791.45,
      "text": "gets back to that thing where you know, all your keys are in one place, it's, it might be cryptographically secure, but, the physical nature of bringing all the keys together is sort of the sketchy part."
    },
    {
      "speaker": "stephan",
      "time": "30:03",
      "start": 1803.02,
      "text": "Gotcha, yeah, okay. So is it a like hard line requirement that all the devices- Addresses have to be physically present for setup. So as an example, let's say you were in different countries, right? I'm in, I'm in Dubai, I'm in the UAE now, let's say you, you're probably in Australia or somewhere. That's right. Like, how would we do it then? Or can we do it then?"
    },
    {
      "speaker": "nick_farrow",
      "time": "30:20",
      "start": 1820.43,
      "text": "That's a great question. so yeah, I, I envision that you'll be able to have, coordinator software, talking to each other remotely. so I could run, say, Sparrow Wallet or Nunch Our devices into our respective laptops, and we, we could somehow link our, our coordinators so that they forward messages back and forth to one another. in that way, we can still create a frost multisig remotely without having to, to physically connect all these devices into one another."
    },
    {
      "speaker": "stephan",
      "time": "30:59",
      "start": 1858.65,
      "text": "I see, yeah, okay. So, okay, let's, let's talk about the backups aspect of it also. So you mentioned that earlier, can you elaborate on the backups?"
    },
    {
      "speaker": "nick_farrow",
      "time": "31:06",
      "start": 1865.62,
      "text": "Yeah. so Lloyd doesn't like, see- phrases too much, and I, I sort of somewhat agree, like they're, they're not the most-- like they're very user friendly, but they're also very hard to convince people of like how their importance. people lose them all the time, people write them down wrong all the time, or they try and do clever things with them all the time. heaps of mistakes are made all the time. With Frost, seed phrases I think will be sort of an optional thing. I would like to have them because Bitcoiners want to have them and they're, they're what people are used to. It's always nice to be able to, you know, you have your, your long lived Frost, key share or fragment, you might want to convert that into seed words so you can easily, transport it or, or, protect it. But One of the really cool things about Frost is that, and we, we believe this to be true, that the, the multi-signature is quite malleable. And when I say malleable, I'm using this in a, a non-cryptography sense, that- You can add or remove signers to the multisig, at a later date, and this is something you can't do with, current script multisig, so, so if you've got a two of three with script multisig and you lose one of the keys And you're down to, you've only got, you know, you've only got your last two keys left. There's no way for you to add in, a new, participant and make it a, a two of four, and, and likewise, there's no way to remove a participant. So with Frost, we don't have any security proofs for it yet, but we believe it to be possible to not only add and remove signing signers, but also to, to change the threshold, to increase or decrease the threshold, and, and each of those comes with, varying agreement requirements. Sort of most of them, well, pretty much all of them require at least a threshold, number of agree-- parties to agree in order to change the number of signers."
    },
    {
      "speaker": "stephan",
      "time": "33:23",
      "start": 2003.23,
      "text": "Gotcha. So you would be able to change the quorum up or down, yeah, in this context. So how would you change? So I'm curious then, would you need a-- Okay, put it, maybe this is like an inception question, but do you need a quorum to change the quorum? Is that, is that how it works? Yeah, yeah,"
    },
    {
      "speaker": "nick_farrow",
      "time": "33:38",
      "start": 2017.78,
      "text": "yeah. Yeah, that's, that's, depending on what you're changing, we haven't fully got to the bottom of it all, but say you have a three of five and you wanna make it"
    },
    {
      "speaker": "nick_farrow",
      "time": "33:51",
      "start": 2030.51,
      "text": "Three parties to, to, to collaborate in order to add a, that sixth party. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "33:59",
      "start": 2039.04,
      "text": "Or even to cut someone out. So let's say you're going from three or five down to three or four, and someone's getting cut out, like, you know, it's the same kind of thing, right? Right. And,"
    },
    {
      "speaker": "nick_farrow",
      "time": "34:06",
      "start": 2046.2,
      "text": "and, and the reason that that's okay is because, the security ass- assumption of Frost is that you, you have T, a threshold number of honest parties. So if, if you've already got, three- People who are willing to decrease the threshold and make it less secure, then, or, or kick out other, other signers, well, then they could already steal the funds in any way, so it's, it's no less- Yeah. I think"
    },
    {
      "speaker": "stephan",
      "time": "34:32",
      "start": 2072.08,
      "text": "that's, that, that part's kind of fair, but I think, for me, it's more just a question of, you know, you would want to see the implementation has been out and battle-tested out in the wild for some time before, you know, if I would, you know, I, I use, you That setup, unless I was very confident that it had been out there and tested for a while with, you know, multiple hardware, multiple sets of software. I think that's also part of the, the reason for being so dogged about seeds, I think, for a lot of Bitcoiners is because they're focused on verifiability and being able to recreate things, right? Because if you put them into-- if you put a Bitcoiner into a, let's say, let's say, seedless context or quote-unquote seedless, they're now having to place a Whereas if you have their twelve or twenty-four words, it just-- at least the way I'm seeing it, it's more reproducible, it's more verifiable. I sort of, I know what's happening. I can-- I don't know, maybe, maybe it's also a, a familiarity thing because let's say I'm using Coldcard or some other device, and I'm doing dice rolls to, you know, I can-- it just kind of having that gives me a little bit more that I can do to make it verifiable, and I think that Seedless style approach. Yeah, that's a really good point. That's a really"
    },
    {
      "speaker": "nick_farrow",
      "time": "35:53",
      "start": 2153.03,
      "text": "good point. You can always, take that seed and, and put it in like a, yeah, like an off, offline computer or another hardware device and verify it, very easily independently verify that that's reproducing, the same, the same private keys you expect. Right, the same seed or the"
    },
    {
      "speaker": "stephan",
      "time": "36:09",
      "start": 2169.12,
      "text": "same private keys, exactly, right? Because I wouldn't wanna just be kind of placing all my trust in the software because, hey, it's, you know, I don't wanna scare listeners, 2020, there was a malicious alert from Electrum. Now, at the time, Electrum was a very popular wallet for OG users, and there was a malicious alert, and some users clicked it, downloaded it, guess what? It was malware, and there were users who lost coins out of that. So I think that kind of thinking, it can be very, jarring and make it difficult for people to sort of place all their trust in one piece of software. It's, you know, the, the way I view multisig, as, you know, my friend Michael Fl explains, it's about fault tolerance, right? How can you set things up in such a way that even if you made a catastrophic error, you still don't lose your coins, right? Because maybe there was a supply chain risk, or maybe there was a problem in the cryptogra-cryptography of how it was implemented in one of those devices, or maybe it's a problem in the secure element, or maybe, you know, you're keeping your devices in different locations. I think it's all about having more fault tolerance, but being done in a way that's, you know, reproducible, You know, maintaining seeds, and that's why I'm in the maintaining seeds camp personally, but, it'll be interesting to see what way it develops."
    },
    {
      "speaker": "nick_farrow",
      "time": "37:27",
      "start": 2246.74,
      "text": "Yeah. So I, I do really like having, The seeds is at least an optional, that you can, you can always backup your Frost, key share to a seed. And other ideas we have is sort of these NFC backups, so you might be able to like write it to a, to an NFC chip, so you can easily load it up again. you could even have, say, one Frost device that you just, much like a seed signer, you load up individual secret, you load up a secret share, sign, wipe it, load up the next secret share, sign, wipe it. Still probably not ideal if, if you would believe that device is compromised, but it's, it's cool that you can do that. so yeah, NFC backup and you could maybe,"
    },
    {
      "speaker": "stephan",
      "time": "38:10",
      "start": 2289.91,
      "text": "yeah, you could maybe argue, oh, okay, I'm okay with, you know, for some people, they may be okay with having one or two of the devices as NFC because, because I'm using multisig already, right? So there's kind of a benefit of that."
    },
    {
      "speaker": "nick_farrow",
      "time": "38:21",
      "start": 2300.87,
      "text": "Yeah, it's, it's moving the security away from trying to have a, a super secure single device to having Risk across multiple devices. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "38:34",
      "start": 2313.98,
      "text": "Yeah. And of course, maybe the, the truly paranoid may say, \"No, I want, I want a device with a screen and a, you know, for every single one of the devices in my quorum, because I just, that's just the, the, the security bar that they wanna set.\" Or as a company, maybe they're, they're just securing that much money that that's the minimum threshold. But maybe for smaller businesses, smaller amounts, it kind of makes sense to have thresholds where maybe one of them has an NFC or something like this"
    },
    {
      "speaker": "stephan",
      "time": "39:00",
      "start": 2340.5,
      "text": "Devices. Is there any-- put it this way, is there any additional computational requirement on the hardware devices, or would say a typical hardware device today have enough, grunt, let's say, to, to do the processing? They have"
    },
    {
      "speaker": "nick_farrow",
      "time": "39:14",
      "start": 2353.86,
      "text": "enough grunt. it's an interesting question Frost does get computationally expensive when you start, when the threshold is really high. So if you're doing like a, like I don't know, like a fifty of a hundred, it could take a few minutes, but I don't even-- No, I don't think anyone's doing multisigs of that size yet, but actually Quite a, a funny comment I saw on GitHub a few months ago on, so Jesse Posner is one of the people who have a Frost, implementation in the works, to, to, libsecp256k1 and, zkp, and he, i-in his PR, one of the guys from like this Wall, the Wall Street Bets, sub-subreddit left this comment asking like, \"Is it possible to do a...\" See, see, three million out of four million, person frost multi-sig because they wanted to have this, this sort of user, user decided investment fund where the users would vote on what they were gonna, you know, buy for the week or, or whatever. at the moment, things like that are, are sort of computationally too intensive. it, it requires, once you have a really big threshold, you have to do a whole bunch of elliptic curve- Of, multiplications which are, are quite costly. But, but for the moment, for doing, you know, your, your personal or, you know, anything up to, yeah, I'd say like around a fifty out of a hundred, you're, you're probably more than nothing to worry about with existing hardware, abilities."
    },
    {
      "speaker": "stephan",
      "time": "40:56",
      "start": 2455.76,
      "text": "Yeah. I think it's interesting because sometimes things get revealed in practice, right? So as an example, I've heard of cases where, when people are signing, you know, we're talking here in a script multisig context, They are signing a transaction with many UTXOs, and they've got an older hardware device that's part of that quorum. And so they're sitting there, and the device sometimes it takes, you know, three or four minutes to sign that transaction because there's so many UTXOs and they're multisig, it's more complicated. and in some cases, I've heard of situations where people had to break the transaction down into smaller outputs, right? Like literally Yeah, well, like, try the transaction with smaller outputs, yeah, because it literally wasn't able to, you know, handle it, because maybe it was an older device, like, the, the original Trezor device or something like this, right? Interesting. So it might be a similar case where, you know, and you'll, you'll never, Foresee every little, you know, edge case of how some person tries to use it, right? As you said, in the Wall Street Bits example, where they might wanna do some crazy three million out of four million thing. But, yeah, I think potentially some benefits there for the, companies or maybe people with a lot to secure and maybe they really want the privacy benefit out of it."
    },
    {
      "speaker": "nick_farrow",
      "time": "42:10",
      "start": 2530.16,
      "text": "I wonder with that, the, the, the slow multisignatures you just mentioned, I wonder if that is a, a symptom of it being a- Script multisig, I'm, I'm not exactly sure, but perhaps because Frost isn't using Bitcoin script, it doesn't have to do this sort of, perhaps less For each UTXO there might be less work, I'm not sure, I'd have to look into it. But, yeah, perhaps because you're not using Bitcoin script, you could avoid some of this computational, cost. Oh,"
    },
    {
      "speaker": "stephan",
      "time": "42:41",
      "start": 2561.02,
      "text": "okay. Yeah, I'm, I, I don't know enough to, be able to comment on it. Okay, so we've spoken about Frost, what about-- So in terms of Frost, in terms of where is it, where is it at today, implementation-wise, cryptography-wise, is this all kind of like highly experimental or like"
    },
    {
      "speaker": "nick_farrow",
      "time": "42:58",
      "start": 2577.59,
      "text": "Yeah, so the, the Frost paper, is, is proven secure, so that's a great start. As I mentioned before, Jesse Posner has an implementation of Frost in C, and that, I view that as sort of the more, official implementation, the more robust one. It's, it's being vetted quite heavily, by a whole bunch of people in, in that GitHub, pull request. Lloyd and I have our own Frost implementation in the, in his secp256k fun library, which is a, a very fun in the name and a sort of experimental cryptography library. so we have our frost implementation in there, and we're, we've been tinkering a whole bunch with it, trying to make it really user friendly and be able to do really powerful stuff with it. so those are the two I know of. I have seen there are other non-Bitcoin related frost implementations. implementations, so there are Frost implementations that work with elliptic curves that, that Bitcoin doesn't use, and, and those are presumably being used for o- other altcoin stuff or who knows what. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "44:12",
      "start": 2651.95,
      "text": "And so I guess the next things would be sort of advancing it forward, maybe looking at, maybe you would try to lobby some of the hardware devices, hey, can you please support this thing? Or lobbying, you know, some of the wallet, software coordinator, software to support the thing and find a way-"
    },
    {
      "speaker": "nick_farrow",
      "time": "44:27",
      "start": 2667.34,
      "text": "Yeah, so, so there's a few, there's a few angles we need to, to get things working on. one really big one is going to be, the Frost specification. So getting Jesse's implementation of Frost compatible with our implementation with Frost, compatible with whatever other implementations of Frost are out there. so that's gonna be one really big step and sort of a, a very important early on one. once we've done that, I'm really keen to, to check out, some of these existing- Software wallets and see if we can add in a, a frost coordinator, that, that can talk to these, frost hardware devices that we've been exploring. that, that would be, yeah, the next sort of step for me, I think. Gotcha. Would be, to get these going."
    },
    {
      "speaker": "stephan",
      "time": "45:13",
      "start": 2713.05,
      "text": "Okay."
    },
    {
      "speaker": "nick_farrow",
      "time": "45:13",
      "start": 2713.43,
      "text": "Yeah. So we've"
    },
    {
      "speaker": "stephan",
      "time": "45:14",
      "start": 2713.87,
      "text": "spoken about frost, what about roast? What's roast?"
    },
    {
      "speaker": "nick_farrow",
      "time": "45:17",
      "start": 2717.05,
      "text": "Yeah, roast is a little bit misleading. When people hear the name, they, they assume it's sort of its own signature scheme. You know, you've got It's not quite like that, so, so Roast is actually a, a wrapper, it is a, a set of instructions for how to run a threshold signature scheme like Frost. The example of when Roast is required, the one I like to give is imagine you, we're, we're on, we're a part of a company or say, say we're a part of a charity, and say we wanna donate money to, say, Satseal, and I might not actually want to donate the charity's money to Satseal. So what I'll do is, when we go to sign with Frost, I'll say, \"Yeah, I'll sign, I'll sign. Give me the, the PSBT or whatever, I'm ready to sign.\" But when it actually comes around to my turn to sign, I just sort of disconnect, I log out for the day, and, and you guys are just left hanging there, waiting for my signature. And maybe I eventually come back online and say, \"Oh, yeah, I'm, I'm back now, I'll sign Again, once again, I just, I just flat out refuse to sign. So with Frost, signers can be disruptive, they can, they can sort of pretend that they're willing to sign things or, or they can have really bad connections and they can disappear, which prevents things from being signed. What Roast is, it's a set of instructions for, which signers to choose at each signing round. So if I disconnected on that signing round, like, you know, you give me an an hour and I'm still not logged on to sign, what you would do is you would, your Roast instructions would tell you, \"Let's kick Nick out, he's a malicious signer. Let's go ask one of our other, signers of our multisig.\" to, to help us sign this, this message. So, so Roast is a, a set of instructions that makes Frost robust. and, and provided you have T, a threshold number of honest signers, you're guaranteed to eventually arrive, at a signature, when you're using Roast."
    },
    {
      "speaker": "stephan",
      "time": "47:40",
      "start": 2859.58,
      "text": "So as I'm understanding it, is it suggesting another signer to go to? Is that essentially what it's doing, or is it- Or is it a system that recognizes, like, if, let's say in that example, you're grieving and I should go to Lloyd for a signature instead of you, is it gonna tell me that or how, what's, like, how does that work?"
    },
    {
      "speaker": "nick_farrow",
      "time": "47:58",
      "start": 2877.67,
      "text": "So, so one of the, fundamental requirements of Frost is that you have what are called identifiable, identifiable aborts. And so whenever I, say I, I didn't actually sign, I, I give you gibberish back, you're able to look at the gibberish I gave you You and say, \"Nick, you're, you're not actually signing, you're just sending me garbage.\" And then Roast will tell you, \"To essentially, yeah, Mark, Nick, malicious. Let's look at a different subset of, of signers.\" So Roast really sort of, it keeps track of who's a good signer and who's a bad signer, and, and you, you can continually sign using those lists."
    },
    {
      "speaker": "stephan",
      "time": "48:40",
      "start": 2920.09,
      "text": "Gotcha. So it would make more sense in bigger quorums, let's say, right? Whereas, let's say a small quorum, two or three, everyone knows each other and they're all good friends, like it's unlikely you would need that there, right? But let's say it's a bigger thing, like fifty people or, you know, thirty people in a quorum somewhere, so for whatever reason, if some of them go malicious, although, I mean, if you all work in the same company together or you're in a charity together, I guess it would be kind"
    },
    {
      "speaker": "stephan",
      "time": "49:05",
      "start": 2945.22,
      "text": "of"
    },
    {
      "speaker": "stephan",
      "time": "49:10",
      "start": 2949.87,
      "text": "Bad, you know, something like that."
    },
    {
      "speaker": "nick_farrow",
      "time": "49:12",
      "start": 2951.57,
      "text": "It, it does also help in that situation as well, when someone's got, yeah, a, a bad internet connection, you can keep track of which signers are sort of, reliable, which, who, who has been successfully signing, and, and you can continually go to them f- as your first point of call whenever you want something to be signed. Gotcha. So"
    },
    {
      "speaker": "stephan",
      "time": "49:33",
      "start": 2973.0,
      "text": "would you-- wouldn't you manually select or not really? Like, so I guess in the current-- like, I'm, I'm thinking of legacy Like, oh, okay. Let's say I've got a, you know, some other device, I'm gonna sign it with device B instead of device C. Or, I, I guess the way you're explaining it here is almost like the software, the coordinator is kind of auto-picking who I go to for a signature?"
    },
    {
      "speaker": "nick_farrow",
      "time": "49:55",
      "start": 2994.89,
      "text": "Yeah, exactly. And, and Frost, Like, the algorithm itself is actually relatively simple. It's sort of, yeah, it's just keeping track of these, these, who's a malicious signer and, and who has been a, responsive signer and, and sort of, sort of updating that a-as you, as you would quite expect. but yeah, like you say, if you're, if you're running your own, say two out of three self custody multisig, you'll never need Frost, to, you, you know, you can, you can trust your, yourself to These devices and, and, and get signatures from them, and yet even in a company it might not be so useful, but in this sort of, these gray areas where it could be a little bit adversarial, you could be in a multi-signature with people that, you, you don't have much in common with, you don't- Yeah."
    },
    {
      "speaker": "stephan",
      "time": "50:46",
      "start": 3046.35,
      "text": "Or maybe it's like for a bet. You know how people do these bets online, and maybe there's like a multi-signature amongst people who kind of don't trust each other 'cause maybe one of them won the bet"
    },
    {
      "speaker": "stephan",
      "time": "50:59",
      "start": 3058.68,
      "text": "Then what are some of the, others? Oh, you've also, you've been playing around with Nostr as well, right? What's the, what's the deal there?"
    },
    {
      "speaker": "nick_farrow",
      "time": "51:07",
      "start": 3066.7,
      "text": "Yeah, Nostr, has been a lot of fun as of late. so, it-- because Nostr uses Schnorr signatures to sign, i-it's posts and, and everything flowing around on Nostr, you could view Nostr as sort of like a really fun playground for, for Schnorr signatures, and it's a lot less risky to- To, you could be a lot more reckless on Nosta, with shaw signatures, you know, the, the worst that could happen is you-- someone takes over your Nosta account, whereas with, with Bitcoin, if you're doing risky stuff on Bitcoin, you know, you could lose a lot of funds. So, so one of the things I, I did a little while ago was Nosta plus Frost is, is Nosta. Oh, sorry. Yeah, Nosta plus Frost is Frosta. And with Frosta, it-- I think it might be the world's first collaborative social Media account or shared custody social media account."
    },
    {
      "speaker": "stephan",
      "time": "52:03",
      "start": 3122.54,
      "text": "It's kind of like a multisig for social media."
    },
    {
      "speaker": "nick_farrow",
      "time": "52:05",
      "start": 3125.3,
      "text": "Exactly, exactly. so you and I could each have a, a key share of a multisig, and in order to sign, it could be a two of two or a two of three. in order to post under that, that nostr account, you need some, some threshold number of, of multisig members to, to each sign the post."
    },
    {
      "speaker": "stephan",
      "time": "52:25",
      "start": 3145.01,
      "text": "I see. So it could be useful for people who have like a massive social media following, maybe they've got a- team who manage, you know, if you're Joe Rogan or, I don't know, someone who like has a big following, and, you know, instead of trusting one person with your password for Twitter or Nostr or whatever, or your private key for Nostr, let's say, maybe this would be a way to share it around, I guess, kind of-"
    },
    {
      "speaker": "nick_farrow",
      "time": "52:45",
      "start": 3165.39,
      "text": "Yeah. I, I like to say it protects against the, the rogue intern attack that, yeah, you, you give the intern, you know, full free rein of your, of your social media and, And, and social media accounts get hacked all the time from like big companies. They always end up posting like NFT scams and, and you know, scamming a whole bunch of their, their customers. You see it happen all the time. So yeah, having this shared custody of social media, is a, is a pretty novel idea, I think, and hasn't, hasn't fully been explored. Yeah. One related idea on that is that This Frost star is probably what Ethereum DAOs should have been. you can, a DAO probably should just be a big multi-signature where, where people sort of sign things to vote on what the, the organization does or what changes it makes to itself, and that same multi-signature, can protect, the DAO treasury or, or whatever. And, and this carries forward Forward to ideas like, Fedimint, so you might want to have a, a shared Noster account for a federation that whenever they're, you know, they're deploying an update to Fedimint or they're, they're, making some changes to their security setup or something, they can publicly post this, under a federated Noster account, as opposed to giving, you know, giving one federation complete control of the, of the social media"
    },
    {
      "speaker": "stephan",
      "time": "54:24",
      "start": 3264.29,
      "text": "Gotcha. And I guess that could also stop the malicious update sort of, or at least it might help stop the malicious update thing because if it's just, let's say, single sig, website, I mean, obviously we're not real, but you know what I mean? Like a website that's under single, a single person's control, this is kind of like having multi-sig without, without having a token. So I think that's the other interesting thing. Obviously, a lot of the Shitcoin people, they're-- The thing I see, the criticism"
    },
    {
      "speaker": "stephan",
      "time": "54:54",
      "start": 3294.11,
      "text": "Personality. They're about the Ponzi or the rug, you know? That's kind of like, they're, they're, you know, because they want a token that they can dump on someone or the NFT, ordinals, inscriptions, people are really, you know, that's what it seems like to me at least. so this could be an example of, hey, you don't need a token for that, you can do that with Frostra as an example. Although,"
    },
    {
      "speaker": "nick_farrow",
      "time": "55:12",
      "start": 3312.02,
      "text": "right, it's just a, it's a key pair, it's like a shared, In this Frost multisig, you could program all kinds of functionality that moves the treasury funds around or, or you could add rules which change the"
    },
    {
      "speaker": "stephan",
      "time": "55:35",
      "start": 3334.7,
      "text": "voting, the governance, the governance. Exactly,"
    },
    {
      "speaker": "nick_farrow",
      "time": "55:37",
      "start": 3336.78,
      "text": "exactly. I, I agree. I haven't actually really seen any DAOs yet that I'm like, \"Oh, that's actually a good idea.\" Maybe the Wall Street bets one is interesting, like having, you know, like a, a user directed, investment fund is an interesting idea, but, yeah. I don't know if it's actually a good one."
    },
    {
      "speaker": "stephan",
      "time": "55:56",
      "start": 3355.63,
      "text": "Yeah, it seems many of them in practice are centralized in some way, shape or form, or there is some kind of backup multisig, you know, there's some, you know, backup thing that the admin keys, yeah, admin key, right? So, and you could say, okay, even, even if, let's imagine we had Frost or Naver or using Frost, there might be some other problems too, right? Maybe there could be some kind of Sibill attack, how do you stop, you know, people just representing Let's bring it back to Bitcoin, yeah. What do you think of the future of multisig, right? Like if we're, if we're looking at this and we're thinking about what Frost and Roast might do, do you foresee a lot of companies or la-- you know, charities or maybe high net worth individuals adopting this kind of thing or even just everyday, you know, just average users?"
    },
    {
      "speaker": "nick_farrow",
      "time": "56:45",
      "start": 3404.93,
      "text": "Yeah. Absolutely. I, I think the, the user experience is going to be, has the potential to be so much more accessible than, what people may have experienced with, script multi-signature. I myself, when I first tried to set up a script multi-signature with Electrum, a few years ago, I was like, \"This is scary, I don't, I don't know what I'm doing.\" I've, I've heard it and I've seen it's gotten a lot better, with things like Nunchuk and Sparrow and Spectre, but, but I think the, yeah, the user experience that's possible with, with Frost keys, is to a wider group of people who aren't necessarily hardcore Bitcoiners, especially when you're bringing in these ideas of having this malleable, multisig. So, yeah, you lose a device, you can easily buy a new one and just enroll it. Or, or if you're of a company and, all the executives each have a Frost key, if one of those executives leaves, instead of having to migrate the whole multisig to a new multisig, you could just blacklist that, that old executive's key and, and re- Issue a new one for a new executive."
    },
    {
      "speaker": "stephan",
      "time": "57:56",
      "start": 3476.47,
      "text": "That's actually a good practicality benefit, yeah."
    },
    {
      "speaker": "nick_farrow",
      "time": "57:58",
      "start": 3478.49,
      "text": "Yeah. So you don't have to migrate the whole thing. I's, i's a really nice feature. And, and it's really awesome that Frost also packages in this sort of this privacy, alongside this user experience improvement. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "58:12",
      "start": 3491.62,
      "text": "But I guess it takes battle testing, it takes time out there in the wild for people to feel, you know, safe with this kind of thing. you know, but, you know, let's see where it goes. So, Let listeners know, where can they find you and find, find your work?"
    },
    {
      "speaker": "nick_farrow",
      "time": "58:27",
      "start": 3507.39,
      "text": "Yeah, I'm, I'm on Twitter at u t x o club and my website domain is u t x o dot club. We don't have any, frost related social media yet, but I plan on making some soon once we've, once we've got a, a product ready to unveil to you guys. so yeah, follow me at u t x o club and I'll, I'll be posting about it there. Excellent. Thanks for joining me, Nick. Thank you very much"
    }
  ]
}
