{
  "episodeId": "SLP506",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "stephan_livera": {
      "name": "Stephan Livera",
      "role": "guest",
      "tag": "STEPHAN"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:08",
      "start": 8.47,
      "text": "Hi, you're listening to Stephan Livera podcast, a show about Bitcoin and Austrian economics brought to you by swan dot com. Today my guest is Andrew Polstra. He is director of research at Blockstream. He is a long time Bitcoin researcher and developer, and we're talking about this concept of a paper computer. So in this episode we talk about Bitcoin private keys today contrast Multi-signature and Shamir secret sharing, as well as various aspects around where you keep those shards, and then we get into this concept of a paper computer and what it might be useful for. Now, just a quick note, as this episode went a little bit longer, I thought it made sense to split this down into two parts. So the first part is more focused on Codex 32 and the paper computer, and the second part will be more focused on research cryptography, Bitcoin directions, and now onto the show with Andrew. Andrew, welcome to the show. Hey, great to be here. So, Andrew, I know you've got a, a book coming out soon, and of course, you're director of research at Blockstream, and, obviously there's lots of, Bitcoin things that we can get into. You're a wealth of knowledge on all these things. Every time we speak, I'm, I'm always learning something new. But, let's start with the, with the Codex 32 stuff. So, do you wanna just set the scene for people in terms of Typical thing. And then why, why, what, where did this idea for a Codex32 come from?"
    },
    {
      "speaker": "stephan_livera",
      "time": "01:33",
      "start": 92.62,
      "text": "Yeah, yeah. so today, right, most people, people who are custodial, you know, not your keys, not your coins, people who are self-custodial, their coins, they probably got their coins, let's look at a hardware wallet, right? They've got a ledger or a cold card or a Trezor or something like this, right? And then they've got some seed words that they backup, and those seed words kind of, all of And the kind of the, the biggest, most important and difficult part of self-custody is, is not only, you know, keeping track of your hardware wallet, but keeping those seed words stored somewhere securely. So the issue is roughly that you want to store it somewhere, you know, secure. You probably want, you probably don't wanna have it written on paper, you might wanna have it in like a crypto steel or something like that. But then how many copies of this and where should you store these copies is a question that you've gotta ask yourself, and there's kind of a trade-off that you have to make where the more accessible or the more copies you have or, or, you know, the, the greater the likelihood that somebody, some bad person, is going to take it, Somehow it will fall into the wrong hands, where the wrong hands is pretty much anybody but you, right? And then somebody else has your keys, and then they can derive your addresses, they can spend your coins, they can take all of your coins, right? But the trade-off though, is that the less accessible and the fewer copies you have, the greater your risk that you're actually going to just lose things, right? and then nobody has your keys, and that's not really a lot better than having them stolen, right? Because then the, the bitcoins are gone. So there are to, to address this, which is to use a multi-signature, and I, I would strongly encourage anybody who can use a multi-signature to, to do so, right? So all the, the major hardware wallets now have some form of multi, multi-sig support, and they're generalizing it and doing, miniscript support, and you can do all sorts of interesting signing policies, where you have multiple keys and then multiple seeds, and then you can store these in various ways and, and, kind of make the trade-off in, in a nicer way,"
    },
    {
      "speaker": "stephan_livera",
      "time": "03:37",
      "start": 217.1,
      "text": "Two of them to move the coins, say. And so now you can have three different backups that are in, in three different places. If somebody steals one, well, one isn't so bad because they can't steal the coins of just one, and if, and if you lose one, that's also not a problem because you still have two, right? So you're able to make this more nuanced trade-off. But the issue with multisig, there, there are a couple technical difficulties. It's a little bit more expensive on chain, you need a newer, harder wallet, you need, you know, it's a bit of a, a more difficult process to take care of. And a lot of people have coins that are, you know, they've been storing for a long time or plan to store for a long time, and the complexity of dealing with multiple keys or the complexity of just moving their coins at all onto a new system, maybe they, they don't want to deal with. And so they Just like a single seed lying around, and, or maybe they are using a multisig, but then they still have these individual seeds in the end that are lying around. And it would be nice if we could still deal with the backup problem, right? So using a multi-signature, you're able to have, you know, different keys, and then you're able to make a trade-off there. But the idea behind Shamir secret sharing is that for the individual backups, you're able to make a kind of the same trade-off, the same kind of, same kind of threshold trade-off, between having multiple shares and for having, having multiple backups that are distributed and maybe fall into the wrong hands versus having too few and then worrying about losing them. So the idea, in, in summary basically, is that with Shamir secret sharing, you have your seeds, whether it's part of a multisig or whatever, you have your actual seed data, and then without touching the blockchain, without interacting with anybody, without really doing anything with your wallet even, you can split that up. And so this single physical backup, you can now kind of split it up, and then when you want to use it To recover your hardware wallet, you have to bring it back together. So the idea is that if, you know, if you're willing, maybe you don't want to bring your seeds, all your different shares together every time you spend your coins, but you're willing to bring your shares together every time you reconstruct your hardware wallet, that's a situation where you might want to use Shamir Secret Sharing. And the benefit over multi-sig is really just convenience, like I really wanna emphasize that. Like if, if you have the choice and the technical means and you're willing to, to spend the fees or The Shamir secret sharing is nice because you don't need to change anything and it's convenient, you can kinda do it just by dealing with your seed data, without dealing with the blockchain, without dealing with your wallet. That's the"
    },
    {
      "speaker": "stephan",
      "time": "06:04",
      "start": 364.2,
      "text": "idea. Got it. Yeah. So as you were saying, many people today are using a, a typical, BIP thirty-two based scheme where they have twelve or twenty-four words chosen from the BIP thirty-nine word list, and typically many people are just using single signature standard setup, and maybe, let's say the intermediate people, and maybe there's a, There are people out there who love their single signature with a passphrase, right? So it's like an extra, you know, few words. And then, let's say the advanced users are out there doing multi-sig. But I guess what we're talking about here is this concept of Shamir's secret sharing, and it can be used in combination with multi-sig as an example. I don't know, for example, I know Trezor and Unchained Capital both incorporate, you know, or have some capabilities with Shamir's secret sharing. I know Trezor has it inbuilt in"
    },
    {
      "speaker": "stephan",
      "time": "06:54",
      "start": 414.31,
      "text": "If you have a default Trezor, I think it's there in the Trezor Suite, and I know Unchained have Hermit, which is also sort of using a sim- using the same technology in the background. But I guess let's, let's contrast then, like you said, Shamir's Secret Sharing and Multi-Sig, even if the-- even if they're not necessarily always conflicting, the-- I think the important aspect I noticed, and you, you do call this out in the book, from what I saw, is that when you need to go to spend,"
    },
    {
      "speaker": "stephan",
      "time": "07:25",
      "start": 444.65,
      "text": "That's really where multisig is probably more practical, right? Because then in that case, you could set it up where you've got, you know, three locations, five locations, so that way you're just going around with, with the partially signed Bitcoin transaction, the PSBT, and so in that way, maybe there's a little bit more of a practicality into-- or let's say security, let's say, but with decreased practicality. What, what do you think?"
    },
    {
      "speaker": "stephan_livera",
      "time": "07:47",
      "start": 467.33,
      "text": "Yeah, I think that's a good way to put it, right? I guess like in a one-liner, you might think multi-signature is about your spending policy, right? How do you-- what, what do you need to do to move coins, like who needs to be involved and, and stuff? Whereas Shamir Secret Sharing is about storing your backups at rest, right? So, so when they're, when your backup is just sitting cold, Shamir Secret Sharing is great, but as soon as you need to use it, there's no more benefit, right? Like it's really about sitting cold, and that's probably a lot of what we'll, we'll talk about, is this long-term, long-term storage of cold seeds, basically is what this book is about."
    },
    {
      "speaker": "stephan",
      "time": "08:18",
      "start": 497.7,
      "text": "Yeah. Do you have any thoughts? I know you didn't directly cover this in the book, but do you"
    },
    {
      "speaker": "stephan",
      "time": "08:28",
      "start": 507.57,
      "text": "Fair. This applies whether you're using multisig or whether you're doing Shamir's secret sharing. If you've got some, you know, ten shares Shamir's thing, we, we have to find ten different locations, right? So do you have any thoughts on what's a practical way for people to do that? Is it to rely on friends and family because maybe they're only holding one share or one Shamir's, you know, proportion? How, how do you think about that?"
    },
    {
      "speaker": "stephan_livera",
      "time": "08:50",
      "start": 530.18,
      "text": "Yeah, that's a great question. and it's, it's maybe easier for someone like me Who I, I can, can reach out to, but I would say, yeah, I mean, using friends and family, that's roughly what I do. you might, if you have like an estate lawyer or somebody who's kind of had a long-term professional relationship with you, you might try storing something with them. you might try using a safety deposit box at a bank, although there are lots of, lots of risks there, right? There, there, you can Google for like some, there's a major New York Times story a couple years ago about how banks will sometimes"
    },
    {
      "speaker": "stephan_livera",
      "time": "09:28",
      "start": 567.61,
      "text": "In there, right? Or and you don't really know about the bank employees and so forth. But as an additional, as an additional layer, it's not a bad idea, right? If you've just got one share and you wanna store it somewhere, you know, it'll, it'll diversify your risk. So the main premise probably is that you just wanna diversify your risk. So if you can have multiple locations, so for example, right now I'm staying in the Pacific Northwest of the United States, and there are like five volcanoes within a hundred miles of me right now, for example. so really the, the natural disaster that's most likely to happen would be a volcano. So I would want to have my shares stored, you know, maybe I could have one on my person that, you know, my got hit by the volcano, but then I want some that are far From these volcanoes. And a similar story, if you're in a flood zone, right, or a wildfire zone, or whatever natural disasters might hit your primary location, you ideally want to have shares that are stored somewhere outside of that blast radius. And then a related thing, and this is more into like the, the Bitcoin libertarian kind of, kind of, kind of things that people like to talk about on your podcast, if you're worried about like the government confiscating your things, or worried about organized crime, or worried about kind of jurisdictional, issues. It can also be helpful to have your shares split across multiple countries. so I live in the United States, but my parents are in Canada. it's a very friendly, very porous border, but it is a border, and there, there's certainly value in me having shares stored with family up north, and then I have other shares in the United States. And the idea is that if somehow I were being targeted to have my funds frozen or, or confiscated or something, then there would need to be a coordinated activity on both sides of the border, which is much more difficult than just doing it I mean, the, the, the big word is diversification, right? You wanna diversify your risk. So you wanna think about what are you concerned about happening to your shares, right? Are you worried about natural disasters? Are you worried about confiscation by the government? Are you worried about petty theft? Are you worried about, you know, theft by your friends and family kind of thing? and then try to diversify away so that any one of those, or maybe even any two or three together, Of those things going wrong, you're still going to be protected."
    },
    {
      "speaker": "stephan",
      "time": "11:39",
      "start": 699.43,
      "text": "Yeah. And so can you give us an idea of what kind of numbers are we talking about? So normally when people are talking about multi-signature, the typical recommendations that I, I've seen shared are people saying, \"Stick with simple numbers, something like two of three or three of five.\" What, what do those numbers look like in a Shamir's Secret Sharing context?"
    },
    {
      "speaker": "stephan_livera",
      "time": "11:59",
      "start": 718.54,
      "text": "Yeah. So you've got two numbers. So you've got your threshold, which is the, the two, and like in a two of three, your threshold Is three, right? So you've got the shoe number, the threshold, which is how many you need to reconstruct, and then you've got the actual number of shares that are out there. And similar to with a multi-signature, you probably want to keep your threshold at two or three, right? You can have, you can go up to four or five, six, you know, and in principle, you can have arbitrarily large numbers, but you'll find that trying to get, you know, like five or six different shards together in the same place, that becomes quite a difficult coordination problem. And now you're probably making the wrong trade-off, like you're probably increasing your risk of being unable to get everything together and being unable to execute your process more than you're decreasing your risk of, you know, somebody, 'cause you know, people say, right, like, you know, three can keep a secret if two are dead, kind of thing, right? Like it's very, it's very easy for a single person to just try to steal a single share, but as soon as you go even to two people, it's just tremendously harder, and then three, like, that benefit from going from one to two, and less so from two to three, and beyond that the benefit gets less and less while the cost in terms of, of reconstructing things gets, higher and higher. And then for the other number, the number of shares, let's say you have your threshold at like three, okay? then I would kinda argue have as many shares as you practically can, and in practice, it's unlikely this would be more than like four or five. Like, think about how many like trusted family and friends and lawyers or whoever you're willing to store stuff with. you're probably not going to, to have like a super high number, like you, maybe you have, you know, I'm sure you have hundreds of friends, but you probably couldn't name like ten people who you would separately trust to, to store your bitcoins so, I mean, try to get the number as high as possible, but I would suggest that like you're not going to go beyond four or five, and if you're going beyond ten somehow, then maybe you're actually distributing too many things, and maybe now you're, you're at risk of, Maybe you're making the wrong trade-off there. And then one final point I'll make is that you can actually distribute multiple copies of the same share. So in the way that I've done, my, secret split, I actually have a certain share that I've given to a number of my friends in the Bitcoin space, and because they're all-- they all know each other and they're all from the space, like they all kind of have the same threat model, right? Like they could actually collude quite effectively, and they're also kind of targets from the same kind of crazy,"
    },
    {
      "speaker": "stephan_livera",
      "time": "14:36",
      "start": 875.75,
      "text": "So for all those people, I just gave them copies of the same share. So even if they're all simultaneously compromised, that's no different than any one of them being compromised. And then the distinct shares I would give to like family or to lawyers and so on. So there's another thought you might have, is that you might try to split up your different custodians into different categories, different threat categories, and if there are a bunch of people who all are kind of a correlated risk, maybe just give them multiple copies of one share and try, try to make sure your individual shares are, are at Correlated in terms of risk as you can."
    },
    {
      "speaker": "stephan",
      "time": "15:07",
      "start": 907.25,
      "text": "Yeah, and so the other aspect is if you are trying to combine or combo these things. So let's say you're using multisig and you want to use Shamir's Secret Sharing, maybe for one of the keys, the backups of that particular key in your multisig, then maybe that kind of expands it or makes it more complicated, as well. but maybe that's another thing that you could have like for redundancy. So maybe you have like a two or three, and for that third backup key, that's the one where you're Using Shamir's secret sharing with shards held by different people as a kind of, you know, emergency backup scenario."
    },
    {
      "speaker": "stephan_livera",
      "time": "15:42",
      "start": 941.98,
      "text": "Yeah, exactly. And, and because that's an emergency key, you'd probably be kind of willing to increase your risk of losing it versus the risk of it being compromised, kind of thing, right? So So there's a lot of different trade-offs you can make. I guess one worry, that is very tempting when you have all of these toys and you have the ability all of a sudden to create this elaborate system, is to remember that it has to be comprehensible. You have to be able to describe it in your estate planning documents, and you have to have like something where, you know, your family and, and, you know, a, a lawyer say, who's, is probably a professional, and, and lawyers are very good at like reading detailed instructions, but they're not necessarily very"
    },
    {
      "speaker": "stephan_livera",
      "time": "16:22",
      "start": 981.5,
      "text": "To try to reconstruct whatever crazy thing you did."
    },
    {
      "speaker": "stephan",
      "time": "16:24",
      "start": 983.91,
      "text": "Yeah."
    },
    {
      "speaker": "stephan_livera",
      "time": "16:24",
      "start": 984.27,
      "text": "So there's, there's another kind of meta trade-off, right, between the complexity of your system, and how, how fragile it is."
    },
    {
      "speaker": "stephan",
      "time": "16:30",
      "start": 989.91,
      "text": "Yeah, certainly. I think that's also important to keep it simple enough that your heirs can recover it basically. So speaking of recovering then, that, that's also bringing up the question of how to actually pull the pieces together, in a secure way, right? Because, you know, maybe this space isn't super well developed in terms of, you know, there's not a lot Easily pull together and just throw these shares together and it'll compute it. I mean, does software like that exist? I mean, would it be useful if that was built into existing, well-known Bitcoin wallets? Right."
    },
    {
      "speaker": "stephan_livera",
      "time": "17:02",
      "start": 1021.81,
      "text": "Yep. so there is, so Trezor, as you mentioned, have their, their Shamir secret sharing scheme, right, slip thirty-nine, and I believe that they do have software that will allow you to enter shares. I haven't used it, I don't know. So there's an interesting question of how do you do it securely? Like, can"
    },
    {
      "speaker": "stephan_livera",
      "time": "17:21",
      "start": 1041.44,
      "text": "Share and carry it and so on and so forth. and I, I actually don't know whether or not Trezor supports that, but in, as a wallet developer thinking about how to support that, you know, there, there are different trade-offs that you want to make, right? Because if you have several shares loaded into a Trezor and you're like transporting it and it's, storing that while it's unplugged, that itself is kind of a risk, so there's, there's trade-offs to make there from a, a wallet designer point of view. And we're able to do without a trezor, without any hardware wallet at all actually. And there we have some more and more interesting trade-offs where our intermediate work, you have the ability to go to one location, load a share, go to the next, combine it, go to the next, and like progressively bring all your shares together until you have, Until you have the entire thing. And in the scheme that I'm, I'm going to describe, the intermediate data there is basically stored on a single piece of paper. And in fact, you're able to encrypt it if you have another key, and then you can do, like, kind of arbitrarily, complicate how, how you're doing things, at least while things are, are alive. I, I would caution very much against ever complicating your scheme for storing stuff long term. But when you're actually in the process of recovery, it's okay to have a bit of complication, ' You're going to undo it in the end. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "18:41",
      "start": 1120.78,
      "text": "Now, as you might know, Swan dot com is the place that you can buy Bitcoin and easily learn about Bitcoin, but Swan dot com is also organizing Pacific Bitcoin. Now, for those of you who weren't there last year, it was a phenomenal experience. People had the chance to connect with all kinds of Bitcoiners, whether they are speakers or not, and this time, it's a festival. It's going to be even more than a conference, and it's going to be an amazing opportunity to celebrate Bitcoin, as well as talk to all kinds Of speakers coming, people like Max Keiser and Stacey Herbert, VJ Boyapati, Preston Pish, Greg Foss, Corey Clipston, Lynn Alden, Jimmy Song, and so many more. There will be a main stage for dedicated talks and panels and fireside chats, as well as a swan dome with deep dive sessions and all kinds of activities. So the dates are October fifth and sixth in LA at the Barker Hangar. So make sure you check your calendar, bring along some friends, go get your tickets at pacificbitcoin dot com, use code livera for a discount there When it comes to securing your coins, you still need a hardware device. CoinKite dot com makes the Coldcard Mark IV, which is the latest edition. There is a new device coming out called the Q1, so keep an eye out for that also. But for those of you who have a need now, well, you can go and get the Coldcard. It's got two secure elements, it has NFC support, it's a very reliable performer, and recently they've got a whole bunch of new colors. So you can get it with the gold sprinkling, you can get red, black, features available with the coldcard, and there's all kinds of accessories available over at coinkite dot com. So for example, you can get the seed plate, which is a metal seed backup, you can get the block lock, which is a really cool accessory to have so that you can keep track of the block height and all other statistics. So go and get your gear at coinkite dot com and get a discount on your coldcards with the code livera. And now back to the show. One other area that I was interested for you to explain for us is around hardware wallets. Now, to be clear, I'm not discouraging the use of hardware wallets, I encourage them, but just from a theoretical perspective, can you explain what are some of the risks and difficulties with, quote unquote, trusting hardware wallets?"
    },
    {
      "speaker": "stephan_livera",
      "time": "20:54",
      "start": 1254.15,
      "text": "Yeah, it's a great question. and let me quickly, double down on what you're saying about recommending hardware wallets. So when you're spending coins, right? You've got a, you need a- Some sort of piece of hardware that's going to produce signatures, that's gonna generate addresses for you, that's gonna interact with the Bitcoin network for you. And your choice is kind of either you have a hardware wallet, right, which is kind of, it's usually unplugged and then it can't do anything, and when it's plugged in, it's, it's, you know, maybe it has an air gap if you're carrying an SD card, or maybe it's over the USB bus, and you know, you can, or you, you're gonna have to kind of trust the hardware manufacturer through the air gap, and then you have something that is designed specifically for storing bitcoins. So your other choice, which if you're really technical, I actually would recommend, is to, you know, get a general purpose computer, so like an old ThinkPad that predates Bitcoin, so it can't be compromised in a, in a Bitcoin sensitive way, run Qubes OS or some sort of high security operating system on it, have an encrypted drive, you know, you go do all the things that a hardware wallet would do, but do it yourself and using open source tools, and then you, The kind of person who's naturally going to go do something like that, a hardware wallet is a million times better than just trying to store Bitcoin secrets just like on a normal computer that's connected to the internet and they're using for other things, and you know, who knows? But so this is great for, for producing transactions and like real-time Bitcoin usage But when you start to think about long-term storage and long-term usage of Bitcoin, kind of there are reasons that you should be wary of hardware wallets and about computers in general that sort of build up over time, these accumulative risks. So one kind of the, the meta thing underlying all of this is that you can't really audit a piece of hardware, right? So I've got this nice ledger here right now, if I wanted to know that this was doing what it was supposed to be doing Then I like to say that it wasn't storing any data or that it wasn't implementing an algorithm that I didn't like or something like that. I'd have to pop it open, I would have to dissolve the case of all the chips in acid, then I would have to put it under an electron microscope, and then I would have to infer a layout of the, the chip, and then I'd have to run that through some software that was able to like build a model of the chip, and then, you know, hopefully I have kind of some kind of model for what it's supposed to look like Any data sheets published or anything. it's just like, it's completely inaccessible, and even to the extent that it is accessible, there's not much that I can do. So what could be going wrong here, right? Well, the hardware wallet, it could be bugged, right? So there, there could just be an honest mistake from the, the folks at Ledger, there could be a rogue employee, there could be-- I'm not saying there is, but like, it, it's always a risk, right? there could be a rogue employee, it could be while it was being shipped to me, it got swapped out for something bad. it could be that even with everything working as it should be, there are still side channels. Maybe while it's producing a signature, it's drawing different amounts of power from the USB bus, and my laptop is compromised, and it's able to somehow get from that power signature to something about my secret key data, for example. and it shouldn't be possible, right? This is called a side channel attack, it's a very well-known thing when you Attacks are, are notoriously very difficult, right? You've gotta design your algorithm to not take variable amounts of time or power. Once you do that, you have the right code that doesn't do that, including like kind of surprising things, like you're not allowed to put secret data into array indices because maybe it would cause a cache miss that, that depends on what your secret data is or something like that. There's this whole art of non-obvious programming things, and then in the end, your CPU is just going to like screw you because the CPU is trying to go as fast as possible, and Going to be doing speculative execution and like multiplying some numbers faster than it multiplies other numbers and like doing all sorts of crazy stuff that you can't really predict. So the side channels are, are quite difficult to protect against and also quite difficult, like everything. As an ordinary user, there's nothing you can do, right? Like you could attach an oscilloscope to your USB bus and watch all of the data going and get exact timing. And I have a friend who did do that, and for what it's worth, like we weren't able to detect anything wrong with the treasure or Again, what can you do as an ordinary user to, to kind of convince yourself of this? the hardware wallet has secret data on it. Suppose you try to overwrite that or delete it, do you know it is deleted? Well, assuming they wrote the software properly, then it will actually delete. But even if they wrote the software properly, and even if the operating system of the device doesn't decide that it doesn't want to delete it, and even if your file system driver doesn't decide that it doesn't actually want to delete it because it's gonna delay it or like just log it Maybe like the chip, maybe your flash chip decides not to delete it, because it says, \"Oh, I see you've overwritten this part of the chip, you know, too many times, so I'm just gonna write, overwrite with zero over here instead, 'cause that's better, and I'm just gonna leave that one alone forever. So now your secret data is encased in a physical media that will never be deleted, and there's no way to tell, right? So there's all of these subtle, confusing security issues that come with electronics, and since all electronics, you know, re-regular computers or, or hardware wallets or whatever That as a user, you have no ability or insight into whether this is happening or how to prevent it. And when you're storing coins long term, you don't only, you don't only have to trust it like this particular ledger, say, I can maybe trust that this is okay because I bought it, you know, twenty fifteen or something, and I've been using it ever since and haven't broken yet eventually it's going to die, right? 'Cause these electronics have a finite lifetime, and then I'll have to buy a new one. Or maybe I'll decide that I just don't like Ledger anymore, so I'll switch over to Trezor or switch to Coldcard or whatever. So over the years and decades, there's kind of this continual stream of new hardware, and if any of those are compromised in any of the ways that I've just listed or more, then I'm screwed, right? Then, so it's like this ongoing trusting, it was just cumulative, right? Every additional piece of hardware that I use, there's a, there's this extra risk where it starts out maybe as like a reasonable risk that I'm willing to take for the sake of making one transaction, right? And then the transaction on the blockchain, awesome, no problem. But I don't wanna have I have to, to, to be in a situation where I'm adding the risk from this year to the risk from next year to the risk from, from every year, from so on, until finally it adds up to something that's, that's a non-trivial probability. So what can we do, right? Well, we have some partial solutions to this, right? This is already for most people, they don't try to store their secret data purely, they, they have backups, but they don't keep it just on a hardware wallet. I'm gonna start using the cold card as my demo, 'cause I don't wanna be shilling Ledger too hard. Jade, there we go. This is the Blockstream Jade. I should be, be representing. you, you have other backups, right? You've got like a CryptoSteel or, or something like that, or what, what I like actually is CryptoSteel Tubes. So this is kind of a neat device. So this has got, for those of you who haven't seen this, You can unscrew it and the data, the secret data is there. And this is real seed data here, but what's cool is even though I'm showing it to the camera, you can only make out like one or two characters, probably not even that with the resolution that the camera's at. versus the normal crypto steel where like you leave it open and then, you know, your cousin comes over and takes a selfie and now there's a photo of your secret data, you know, who knows where. Right. I like these. These are also nice 'cause you can drill holes and stuff and drop them in, so it's a lot easier to do Jason Bourne kind of things. But alright, alright, you got this. Right."
    },
    {
      "speaker": "stephan",
      "time": "28:25",
      "start": 1705.24,
      "text": "Yeah."
    },
    {
      "speaker": "stephan_livera",
      "time": "28:26",
      "start": 1705.72,
      "text": "So we're already kind of familiar with, you know, you have your backup, you have your seed, let's put it onto,"
    },
    {
      "speaker": "stephan_livera",
      "time": "28:34",
      "start": 1714.23,
      "text": "into And, you know, ideally if made of, of metal instead of paper, because it's gonna be that much more resistant to fires and floods and, and volcanoes and whatever else you're, you're worried about, then you maybe think about like the mechanical strength of, of these kinda things. so Jason Lop has a series of blog posts where he like puts all these different hardware devices into high- he"
    },
    {
      "speaker": "stephan",
      "time": "28:56",
      "start": 1735.64,
      "text": "tests all the seeds, yeah, things, yeah,"
    },
    {
      "speaker": "stephan_livera",
      "time": "28:58",
      "start": 1738.27,
      "text": "into like hydraulic presses and, you know, dissolves all sorts of horrible things to them. and the benefit of this over a piece of hardware is, not only is it, it's over like a hardware wallet, is not only is it more hardy, but like the security model is something that's really ingrained, like since before we were hominids, we kind of developed the, the mental structures and, and mental tools to keep track of a physical device that you can see. So now rather than having this extremely complicated trust model that involves all these things you can't understand or verify, the trust model for storing this is, you know, you have a, a, a physical artifact, and you need to keep that physical artifact secure. Okay, so that's nice. But now over the years, there's still risk, right? I've got those little steel tiles, right? You can shake them, you can hear them moving around, right? And ideally, I would want to know that the data in here is intact, that it hasn't changed, none of the tiles have eroded, that like, I didn't like just load it wrong many years ago and didn't realize it. you can imagine like, over the years, right? Like, I've got this one on my desk, it's supposed to be hidden somewhere, I need to find another trusted friend. but maybe I just lose track of it, right? Like, maybe I forget that I've got it, and then one day I just like, I And I'm like, okay, well, did the kids do that? Like, you know, how old were they? Did they do it ten years ago? Like, have I run the oven a thousand times with that thing in the back of it? You know, like, you just don't know, right? And now you've got all these things going through, like, is the data intact? Like, what if all the tiles are gone, kind of thing. So it would be nice for peace of mind and for real security, for, for that matter, to have a process where every quarter"
    },
    {
      "speaker": "stephan_livera",
      "time": "30:40",
      "start": 1840.22,
      "text": "or And data has, so seed data generally have a checksum on it, so that it is actually possible without going to the blockchain and without like redrawing addresses and stuff, i-there's, it's possible to check whether or not like individual errors have happened. So BIP thirty-nine famously has like half a word, it's just, it's not a good checksum at all, and, and if, if there's any mistakes in your BIP thirty-nine seed words, with pretty high probability, it will, it will be detected. So with ninety-nine point five percent probability it will be Which kind of sucks. Slip thirty nine is much, much better. So with slip thirty nine, I think you can have up to three or four errors that are guaranteed, one hundred percent will be detected. And if you go beyond that, then your chances are like one in a billion or something that it won't be detected. And another cool thing is that because they use what's called an error correcting code, if you make up to two mistakes, it's actually possible to determine where those mistakes were and what they were supposed to be. So you could have just like any random one of your, your seed words is just wrong, and it's possible for your hardware device to figure out which word is wrong and what it's supposed to be, which is a pretty cool thing. But now we have a trade-off, right? So if you wanna check these checksums, you gotta load it into a hardware wallet, and now you gotta trust the hardware wallet every year, forever and ever."
    },
    {
      "speaker": "stephan",
      "time": "31:58",
      "start": 1917.88,
      "text": "And then we're reopening that whole exercise we were doing before about trusting all the hardware, all the software that's associated."
    },
    {
      "speaker": "stephan_livera",
      "time": "32:05",
      "start": 1924.93,
      "text": "So what you're going to do is you're going to think, \"Well, they're steel tiles, how could they possibly go bad? I'm not gonna take the risk, so I'll just never check it.\" And then one day, fifty years from now, and maybe To your kids or something, and it doesn't work, and the seed data is wrong, and you're like, \"Who knows? You know, this could have happened, this could have gone wrong at any point. In the last fifty years, there could be multiple mistakes, like...\" So what can you do? Well, let me, let me shift gears and talk about my solution here, which is this book here, which is called Codex 32, okay? And what this is, is this book isn't a book about Shamir secret sharing or about Bitcoin, it's not going to tell you, maybe it will tell you new things that, that you didn't know. This book is actually a workbook. Oh, I skipped too far to the exciting part. This is full of worksheets, this is full of tables, and then at the very beginning we've got,"
    },
    {
      "speaker": "stephan_livera",
      "time": "32:59",
      "start": 1978.83,
      "text": "Kind of explaining what we're doing. Right, and you can see we've got all these nice illustrations and stuff that the crypto still drawn in there. We've got these nice drop caps. In the contents of this book, there are two pieces to us, three pieces. The one piece is the tables that I kind of hinted at, another piece of these worksheets, and you can see there's just giant grids of data, and you can tear these out and you can, fill them in. And then the third piece are these paper computers. These are called Vovels, and you can cut these"
    },
    {
      "speaker": "stephan_livera",
      "time": "33:28",
      "start": 2008.45,
      "text": "Hold one here, so I'm holding this, and you can kinda try not to-- So you can sort of see what's happening here as I'm turning this, there's a window at the top right below the Q Q, and as I'm turning this, different symbols are becoming visible through the window. And every time I turn it, I get a different mapping between characters. And this is actually kind of cool, you can use this, this one for other things. It's two sided, so if you wanted to like encrypt messages, like, maybe you're like a ten year old and you're trying to encrypt messages so your teachers can't read it, you grab this, choose a secret symbol that's going to be your secret key. So maybe let's use the hash tag symbol there. Alright, that's a little, I'm not sure if my camera's showing, but there's a hash tag symbol A unique key that I can then use and basically like build a crypto, crypto RAM kind of thing. So I have three, three of these paper computers. I have this one, which is cool, 'cause it's, it's, two sided. I have this one, which is cool because it has, this is actually a thirty-two by thirty-two lookup table, is what this one does. So there's all these little windows on the front, on the back, there's a thousand and twenty-four different symbols, and they're all kind of rotated in such a way that as you turn this Then the third one is the least exciting, but it's also the least used, and this one, you can see all it does is just like a particular mapping from, from letters to symbols. And so the book goes through how you use all of these together and what you can do with this combination of paper computers, which take maybe like half an hour to cut out and assemble. It's, it's good fun. You gotta get some brass fasteners here, you want an X-Acto knife, and, you know, you get to do some arts and crafts. with all of these, you can do Shamir secret sharing, so you can generate a whole bunch of random seeds, random shares, as many as you want, and set a threshold so that any two of them will reconstruct your seed, or any three of them, or four or five. And actually one, one thing I should quickly mention when you're generating your random, Your random shares. What you can do is you can generate these by just rolling dice. And so people are maybe familiar with dice where you may be familiar, like with the, the Colt card, hella way, where when you're generating random data, you roll some dice, you type in the dice, and then that feeds into a hash function, right? Which then scrambles it all up so that your, so that your, your dice entropy is kind of smeared out and becomes uniform. Well, if you're generating stuff by hand, and that's what this all is, this is letting you do Shamir, generating shares, secret splitting, secret recovery, and checksum verification and checksum computation. I'll talk about all of them in a sec. you wanna generate your random data just by rolling dice. Well, if you are a professional gambler or a d&D fiend or something, you may be familiar with the fact that dice are actually not super great at producing uniform randomness. So if you go to a game store or something, you can go-- you always wanna buy the dice that are transparent and have the glitter in them And with the glitter, you can sort of see that it's uniform, you can see that it wasn't like, the dice weren't left in the sun and then like all the weight sunk to the bottom, so it'll always show a certain value. and with they're transparent, you can see that there are no bubbles. But actually, if you look closely, you'll see there are bubbles. In like half them, even the high quality dice that are like transparent, often have these little air bubbles in them, and these are just manufacturing defects, and, and just because it would cost And there's more of them, because those are, those are pretty cheap dice, and nobody's-- I guess people do play Monopoly professionally, maybe. But like, you know, it doesn't matter if they're uniform if you're just playing games, right? So what you can do, using this worksheet-- and again, my camera's having trouble adjusting 'cause there's bright sun-- for these worksheets, you can get the book, by the way. You can buy it on the Blockchain Store, or you can just download it and print it yourself. What this lets you do is de-bias the dice. So if your dice preferentially show like low numbers more often than they show high numbers, or vice versa, or something, by using this worksheet, you're able to go through a process where you can extract uniformly random bits from the dice by just rolling them extra time and doing what's called a Von Neumann extractor. So you generate these random shares. you can then, so suppose you're doing like a three of six setup, a three of six Shamir secret share setup. You generate three random shares by rolling dice. You derive three additional shares by using these paper computers and so on. And then later to reconstruct them, again using the paper computer, you can take any three of those shares, combine them, and get your actual C data back. And here's where this just gets cool. That's already pretty cool, I guess. But here's, here's the, I think the The most valuable part of this whole scheme is that you might worry when you're doing all of these things by paper, by hand. Maybe if you looked at some of these worksheets and you're like, \"Wow, I've gotta like fill in a thousand little squares there while like spinning these paper computers,\" you might worry that you'll make mistakes, right? And you will. Naturally, just like doing repetitive tasks over and over, you spend about an hour doing any one of those worksheets. And, well, okay, if you make mistakes, how can you detect it, right? Like, how, like, if you can't detect the mistake, then, you know, you're worse off than using hardware, because now we've gone from being like having a hypothetical issue where you know some of these problems are, to a pretty much guaranteed, like, humans are going, they can't do mechanical things for a solid hour. And where this book really shines is that it gives you the ability to create and verify a checksum on your secret data. So you generate these random shares, and before you derive additional shares, before you distribute them or do anything else with them, you produce a checksum on the shares. So if you have, one hundred and twenty-eight bits of data, which is a, a good length for, for a secret seed, then that would represent twenty-six characters, or that'll be represented by twenty-six characters in this scheme. So we take twenty-six characters and we're going to add thirteen more. We're gonna make it actually fifty percent longer. But the benefit of this is that now we can detect any eight errors, guaranteed. And if you, if you have more than eight, it's going to be detected, assuming they're random, they're not structured in a way Probably malicious, or you just like grabbed the wrong share. if you have more than eight mistakes, you're going to detect it with probability like one in a billion billion or something. It's just like basically zero. the, I mean, the, the probability for slip thirty-nine was basically zero, and we're like even zero were than that. And if there are up to four mistakes, you can even correct them. Four random mistakes, you can correct them even if you don't know where they are. If you do know where they are, because like maybe one of your CryptoSteel tiles in particular is worn out and you can't read it, then you can correct up to eight. So th-this is why we have such a, such a crazy error correcting code, is that we actually have better error correcting prob-probability Properties, better error correcting p-properties than slip thirty nine here. And we can do all of this by hand. Well, alright, you can compute the checksum by hand, you can verify and detect errors by hand, and we know how to correct up to one or two errors by hand. We think we can probably correct up to four, definitely with a computer you can correct up to four, but we think we can even do the correction up by hand. But we've gotta do a little bit more work, building more worksheets and stuff for this. So, this checksum will allow you to detect whether you make any mistakes while you're doing the generation and distribution of stuff like this. And then even better, you can, every, you know, every year or every six months or however often you want to verify the integrity of your shares, what you can do is you can go fish them out of their hiding place, right? You copy the share data out onto one of these pieces of paper, you fill in the worksheet, and the way the worksheet The checksum worksheet is structured, is that if all the data is intact, then at the end you will get the, the word secret share thirty-two will appear on this worksheet where it seems like you're just doing random stuff for, for an hour, and in the end secret share thirty-two appears. And if you have any mistakes, then it won't, you'll get something different. and the thing that you get, you can use that to figure out where your corrections need to be."
    },
    {
      "speaker": "stephan",
      "time": "41:20",
      "start": 2480.32,
      "text": "Back to the show in a moment. Are you looking for a job in the Bitcoin space or do you wanna skill up your Bitcoin development opportunities? Base fifty eight is a Bitcoin protocol school, so you can brush up your skills or you can learn something entirely new. They have guidance on Bitcoin and Lightning and all kinds of materials that are related to Bitcoin, obviously. And so there are online classes that you can take at your own pace, as well as in-person intensive classes. Classes, and there's a range of material ranging from beginner developers all the way up to expert classes. They have a Taproot intensive class, which is in person, it's coming up soon, and this will cover Taproot, Tapscript, Schnorr, Frost, and Mosaic too. This in person class is coming up just prior to Tabcon in Atlanta from the fourth to the sixth of September, and this class is on again in Austin, Texas, thirteenth to fifteenth of November. So if you want to skill up or get a job in Bitcoin or build something in Bitcoin, go to base And learn what you need there. When it comes to sending Bitcoin on-chain transactions, I always go to mempool dot space to check the prevailing fee market. Mempool dot space is a comprehensive Bitcoin and blockchain explorer. You can see the mempool, you can see the blockchain, you can see transactions, you can see blocks, you can see how many were in this block, you can view a mining explorer, a lightning explorer. It's really just a comprehensive explorer for the ecosystem, and they've got all kinds of features that they are continually developing. So for example, they made mempool blocks scrollable They have a Mempool accelerator program coming soon, so that'll be a great opportunity for those of you if you have a transaction that got stuck, you can go and accelerate that transaction using mempool.space. So go and find out more over at their website, mempool.space. Gotcha. So just a quick question I've got at that point. So from reading the book, it sounds like it's a different scheme, though, to the typical bip39, twelve or twenty-four words, right? So you can't just like, it, it doesn't just map over, right? So I'm curious how you're saying in that example, you got the crypto steel, the cylinder of it, how would you like, or are you saying what's on that is actually not a typical bip39, it's actually done specifically in the codex32 style?"
    },
    {
      "speaker": "stephan_livera",
      "time": "43:28",
      "start": 2608.0,
      "text": "Yep. Great, great question. So the, we aren't using normal seed words for this. we have our separate encoding, we have a different encoding. the coding, encoding is actually the same as B32. So in SegWit, it's the bc1 addresses, you may be familiar, they're all lowercase, the letter B isn't in there, and neither is the letter I or the number one, except bc1, and no more ones after that. or, letter O, I think I have a, right? So you're maybe familiar with So there's no case sensitivity or anything like that. But they're also not words, right? It is just a string of random, random data. So we've con- we've structured the scheme so that if you have a one hundred twenty-eight bit seed, your data, when encoded in this way, will be forty-eight characters, and forty-eight is the number of tiles that a standard crypto steel can fit in one side. So if you have a, a one hundred and twenty-eight bit seed, which is similar to having twelve words in BIP thirty-nine, then it will fit into one side of a CryptoSteel, if you wanted two fifty-six, which is twenty-four words in the BIP thirty-nine, it will fit into both. So we tried to make this kind of compatible with all of the, the devices that are out there. But because it's a different encoding, it means if your, your shares are already encoded in terms of seed words, you either can try to do a by hand conversion from Bip thirty nine or Slip thirty nine into this format, and this is a little bit like ad hoc and, and risky, and then I would suggest you shouldn't do this because you're adding too much complexity."
    },
    {
      "speaker": "stephan",
      "time": "45:01",
      "start": 2701.28,
      "text": "Right. I, I think it's better to sort of, if you're gonna do this, start in Codex thirty two Stay in Codex 32, and if you're already in Bip 39 context, stay in Bip 39 context, right? Yeah. So if you"
    },
    {
      "speaker": "stephan_livera",
      "time": "45:10",
      "start": 2710.42,
      "text": "wanna switch, you wanna start from zero and then sweep your coins, basically, which I think a lot of people will balk at, but that's really, if you're changing your wallet structure, that's really kind of what you gotta do, right? It's gonna cost you some fees, it requires you bring your keys online, you know, like there's, there's risk involved. But the other risk, if you're"
    },
    {
      "speaker": "stephan_livera",
      "time": "45:36",
      "start": 2735.5,
      "text": "But you're, you're grabbing seed data in a way that it's not designed, none of the processes were designed to enable, and so you're kind of going your own way, and, and any slip up could cause you to lose things or have things to be encoded incorrectly. but having said that, I mean, because there is a trade-off here, you know, I think we will eventually have some documentation if you're really gonna like play with fire, we might have some documentation for how to do this."
    },
    {
      "speaker": "stephan",
      "time": "45:58",
      "start": 2758.34,
      "text": "Gotcha. And then could you spell out at a high level the type of use here? I presume this isn't meant to be for your day-to-day wallet, let's say, right? This is meant to be like your long-term hodl cold stack, cold storage stack, and you might rarely ever transact out of this Because every time you do, it's gonna be a huge pain, right? Yeah,"
    },
    {
      "speaker": "stephan_livera",
      "time": "46:20",
      "start": 2779.54,
      "text": "it will be a huge pain, and not only is it a huge pain to transact with this, but you have to load the data onto a hardware wallet to produce signatures, because this book, this book cannot derive addresses. So when you're first starting out, you're gonna need a hardware wallet to, to produce addresses, and it can't produce signatures. So when you actually want to transact, then you're going to have to face the music and deal with all these trust issues related to electronic hardware. Yeah. signatures, can we do address generation and stuff, by hand? And so far the answer seems to be no. We, we spent quite a bit of time kind of like grinding on different algorithms and trying to do stuff by hand, producing like lookup tables that are like books that are this thick and so on. And the, our best estimate with the best techniques that we know of would involve two to three months for an expert working forty-hour weeks doing nothing but spinning these wheels and filling in these worksheets. And you don't know if you make any mistakes until the very end."
    },
    {
      "speaker": "stephan",
      "time": "47:21",
      "start": 2840.58,
      "text": "So in Bitcoin, it starts out as like these cypherpunk guys who are on the internet, and then it becomes more like Bitcoiners are like these Tibetan monks who are like writing in the tomes, for hours and hours, and it's all offline. So, so so far, no, but I mean, it's been fun to talk about. Yeah. But I guess, yeah, but I mean, it's an interesting idea. But I mean, in practice, you then have to still use hardware devices, you know? And so I guess theoretically, you would still have to then input-- So, I mean, walking, like, if I zoom out a little bit and I just walk through what the process would look like, okay? So the idea would be you get this Codex32 book, you, basically cut out those pages at the back, you create the-- into these, volvels, as you said. You would have to go through the process, as you said, is to first generate the Rolling for that, and as you said, the d bias and the dice, then you are generating, I guess, the seed and doing a checksum on that, and at that point, you are deciding the sh-- the Shamir's threshold as well, like three of six or three of five or two of three, whatever. Yep. And then you've got your seed, but now in order to get an address, you'd have to like input that into a device. Yep. And I guess at that point, does the Coldcard or the Blockstream Jade or the Trezor or the Ledger, Anything additional? Like, do they need to support Codex thirty-two? Yes,"
    },
    {
      "speaker": "stephan_livera",
      "time": "48:46",
      "start": 2925.83,
      "text": "yeah, they would need to support the import format. Gotcha. so I've been talking to people, there's a lot of excitement among hardware vendors who I've talked to. They're really excited about this, but it is a, a bit of work for them. So, so right now, there's one wallet that I'm aware of that can do this, which is called Bales. And this is a fork of Bitcoin Core for Tails OS. And Tails is like a high security, it's"
    },
    {
      "speaker": "stephan",
      "time": "49:12",
      "start": 2952.38,
      "text": "It's like, yeah. So there's a guy-- No, I, I, I just, yeah, go on. there's"
    },
    {
      "speaker": "stephan_livera",
      "time": "49:17",
      "start": 2956.93,
      "text": "a guy Ben Westgate who maintains Bales, which is Bitcoin plus Tails, and he is using, a pull request that I made to Bitcoin Core to support this import format. and then other hardware wallets I expect will show up over the next, like, historically for something like this, maybe like six months, six months to a year, 'cause it's not, it's just a new import format, but it's not crazy and it uses the best 32 alphabet, so like a lot of the existing code is already there. but there's just a matter of defining what does the user experience look like, what if you make mistakes, how should the error correction work if you're entering multiple shares, like how many shares do you allow to be entered"
    },
    {
      "speaker": "stephan_livera",
      "time": "49:56",
      "start": 2996.45,
      "text": "To allow partial computation where you enter shares over time kind of thing. So we need to figure that out, and then there's a little bit of technical work, but yes, you, you would need a hardware wallet, that supports it. And so for people listening to the podcast right now, they're probably not going to have one, but I would nonetheless recommend if you think this is cool And you, there will be hardware wallets down the line, and I can guarantee if you, if you obtain this book and then you try to go through all the work, you're not gonna be doing it the next day, right? You're gonna be kinda like, \"Whoa, this is a lot of work, and this is kinda scary, and like, I'm supposed to put like secret data, and if I mess it up, like, the money's gone, kind of thing.\" So you're, you're gonna wanna play with it, for, for quite a while and like, before a reasonable person would feel comfortable using this. Although, I've met a lot of people who are like, \"I wanna use it today.\" So, I mean, Bitcoin, Bitcoin is like a weird bunch, you know? We're not all, we're not all reasonable."
    },
    {
      "speaker": "stephan",
      "time": "50:56",
      "start": 3055.98,
      "text": "Well, maybe for the, the super paranoid, I could imagine maybe for them, but this would be like for the very paranoid, very technical users, perhaps. And I guess the other, the other caveat here is, like we were saying be- we were saying before, these are users who aren't transacting, or at least for this setup, they're not intended to transact very often, because if you're trying to transact very often, then it's just a nightmare, because then you're like, every time you're writing things out and things like this, yeah, yeah"
    },
    {
      "speaker": "stephan_livera",
      "time": "51:22",
      "start": 3082.38,
      "text": "Yeah, you would want. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "51:23",
      "start": 3083.26,
      "text": "But and then I, I guess the theory, so, and I just checked, but just by the way, if anyone's listening, Tails, the amnesic incognito live system, just to check, I think I said it wrong before. But anyway, the point with, let's say you had a, you know, whatever, let's say it's in, in Blockstream, you know, Jade or in a cold card or whatever, at that point, would you then try to wipe it from the device? So that it's, like, let's say you generate, okay, as an example, you generate this setup, you generate the address, you ha- you know the address, you send the coins out of your old setup into this setup, would you then wipe the device at that point and r- rely only on your Shamir's paper volvels or your paper written down sh- shards? Yeah, it's a great question. you could, like, would that theoretically be more secure because otherwise the hot, the keys are living on this device too?"
    },
    {
      "speaker": "stephan_livera",
      "time": "52:12",
      "start": 3131.56,
      "text": "Right, exactly."
    },
    {
      "speaker": "stephan_livera",
      "time": "52:15",
      "start": 3135.04,
      "text": "And you've got the one device that has everything. And I think for the kind of like, if you really like have like your masts all stacked here, and this isn't your day to day spending, like this is money that like maybe you just like don't even plan to move like this decade or like in your lifetime, it should just be like handed down or something, then yeah, I probably would wipe it. and there's one, so so let me actually show the Blockstream Jade for a moment, 'cause the Jade has kind of this neat mode that directly supports this. So the Where you can run your own, and it does some sort of cryptographic handshake where it's able to determine whether the PIN is valid and decrypt your seed without ever receiving any seed data. You can also run the Jade in a mode where there's no PIN server whatsoever, and in that case, it won't store anything. You just like have to type in your twenty-four seed words, and then you can use it, and then you unplug it, and like, well, hopefully you finish what you were doing, 'cause you're gonna have to type them all in again. And yeah, for, for very long term storage where I've got everything on the faucals, I probably would, use a Jade in that mode or even just like find an old laptop and, and write a Python script to do it for me or, or something like that. Because you're right, like storing the data in a single place somewhat defeats the purpose,"
    },
    {
      "speaker": "stephan",
      "time": "53:25",
      "start": 3205.28,
      "text": "right?"
    },
    {
      "speaker": "stephan_livera",
      "time": "53:26",
      "start": 3206.28,
      "text": "Yeah. Although, I mean, there is another reasonable mode where you've got your coins on here and just your backups, and maybe you don't think-- maybe you think like, \"Well, I've got all my coins And so forth. And I don't think that I'll need the backup very frequently. I'll only, basically I'm only going to need it if the Jade dies, basically. At that point, I need, or I lose it, then I need to go get the, the backup. Now, now I'm in a situation where I've got these shares, or I've, I've got the, the seed data on my crypto steel or whatever, I'm not using it day to day, so I maybe am worried about like losing track of it or something, and I don't need it to be very convenient to use, what I need is for it to be, you know, redundant and, and spread out, and then also possible to, Redundant and spread out, but not, but, but resistant against individual parts of being compromised. So for a backup of a hot wallet, the security model also kind of matches what you might want to use the baubles for, right? If you expect your hot wallet will survive on its own for multiple years and then eventually just conk out, right? So I think that's also a reasonable way to use this, is as a backup for a hot wallet, where you can kind of treat it as, treat the backup as a second-class citizen, But have very high confidence that nothing bad is going to happen to it, 'cause like the backup, you, you don't think about it, it's not the main thing, right? It's, it's basically a liability, so better to try to reduce the liability as much as possible."
    },
    {
      "speaker": "stephan",
      "time": "54:53",
      "start": 3292.52,
      "text": "Yeah, okay. So just summarizing then, the idea is, you know, as an example, let's say you did a three of five, Shamir's with those, you know, shards, and the idea being any one of those shards or even two of those shards isn"
    },
    {
      "speaker": "stephan",
      "time": "55:11",
      "start": 3311.28,
      "text": "Three, you know, shards in order to reconstitute the seed and spend the coins. but, the other aspect is it could get difficult, you know, ten years down the line, twenty years down the line. and I know, my friend NVK from CoinKite made that site, walletsrecovery dot org, to try to show, oh, okay, here's the deriv-derivation path, here's the different setups of different wallets we're using to try to make it easy for people, but I could imagine like some crazy situation like twenty years from now, if someone tries to put their coins in Codex 32 and then twenty years from now, it, it could be really difficult to recover those coins, right? If, if it's like another scheme, it's not the typical Bit 39"
    },
    {
      "speaker": "stephan_livera",
      "time": "55:55",
      "start": 3354.63,
      "text": "So yeah, that's, that's a great point, and that's, I mean, that's why you shouldn't like go create your own scheme, which I guess I did, right? Because you, you run this risk. So with Codex 32, everything you need to recover everything is, is inside the book. And the book, by the way, is open source. Like you, you can go to Blockstream, the Blockstream store to buy this like nicely bound one that's very pretty and stuff. But like, I wouldn't, like, I'm not You know, hundreds of copies of the worksheet or like multiple copies of the, the workbook inside of your safe where you can store the entire workbook as part of your estate planning documents, for example. and because what you're doing is, is very close to just like doing the raw mathematics involved in secret, in Shamir secret sharing and, and, and checksumming. Then you have a very good likelihood, for one thing, of the process to survive just on paper, because you have the ability to backup paper in various ways."
    },
    {
      "speaker": "stephan",
      "time": "56:55",
      "start": 3415.38,
      "text": "Gotcha. And then for"
    },
    {
      "speaker": "stephan_livera",
      "time": "56:56",
      "start": 3416.22,
      "text": "another thing, even if all the paper is lost, we're using the same encoding format as B32 addresses, as, as Taproot and SegWit addresses. So the encoding format's not going to go away. And then from there, you know, maybe you'd need to get a mathematician or something, but you would be able to reconstruct everything. And then finally, we have a BIP number. It's BIP ninety-three, and we have a website, which you should think of as, as much less reliable than, than a BIP repo, obviously. But we have the scheme published in, in multiple places. so we've, we've got, certainly BIP ninety-three will tell you everything that you need to recover this. so hopefully the BIPs repo doesn't go away and this, this disappears. the booklet, as I said, is available, and I've been trying to kind of spread can be downloaded and, and you can, you can keep those wherever you keep your other long term documents. So we really tried to make an effort to make this, to make this resilient to times changing and, and the years going by and, and things becoming incompatible. And I would argue that this scheme is much more likely to survive many decades than any individual hardware wallet, right? So in ten years, we'll have different hardware wallet brands probably, I mean, probably the big three, right, Ledger, Trezor, Coldcard, is still gonna be around, but, Things that, that come and go, and some will become big and some will, will become small and so forth. And there are also a lot of different schemes that will come and go for, for how we store stuff. And I think that because we've got the bit number, and because we've got everything is all a self-contained instruction manual, where even if there's no hardware wallets and there's no, like, no wallet support at all, basically, right? You ne- you need the import, you need something that can, can decode the import format. But even if there For doing any of the processes, for verifying the checksums, or for doing the splitting, or doing the recovery, or whatever, you're able to do everything else by hand, and these very nice, you know, beautifully illustrated instructions, which we've designed with the target market, not the target market, but with the target reader being, say, like an estate lawyer who has no idea what's going on and just like finds the book in a pile of old artifacts and just said, like, \"The bitcoins are in the book somehow, you know, read this and figure it out.\" So we, we tried to make it very step by step and very mechanical, how it is that you actually recover this stuff. So, so that's what we've done."
    },
    {
      "speaker": "stephan",
      "time": "59:17",
      "start": 3556.52,
      "text": "Okay, well, yeah, let's, let's see, let's see what, people think after listening to the episode and, having a look at, at the book. I think it's an interesting idea. I, I'm probably struggling to see, like, if I'm already going to the effort of using multisig, I'm probably, maybe for, it's not for website, people can get it there or bit ninety three, I guess people can look that up. And, you know, presumably if Bitcoin is, you know, let's say it goes, you know, it keeps going up in twenty years time, if it's so big and important, then there'll probably be Bitcoin experts who could help someone recover at that point as well. and if Bitcoin goes to zero, well then, we don't have to worry about any of this. Yeah, yeah. So yeah. not that I'm worried about it going to zero, to be clear Polstra ends because that's the Codex 32 paper computer aspect of it. Now, of course, subscribe to the show and be ready for the next episode, which will contain part two of the conversation with Andrew, where we talk more about Blockstream research, cryptography, and Bitcoin future directions, Bitcoin scripting, his thoughts on covenants, and various aspects related to that. So make sure you subscribe, get the show notes at stephanlivera dot com, and I'll see you in the citadels."
    }
  ]
}
