{
  "episodeId": "SLP566",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "dmitry_nedospasov": {
      "name": "Dmitry Nedospasov",
      "role": "guest",
      "tag": "DMITRY"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:00",
      "start": 0.4,
      "text": "Hi, you're watching Stephan Livera podcast brought to you by Swann dot com. Have you wondered how much it costs to hack a hardware wallet? Today, Dmitry Nedospasov joins me. Those of you who have been around for a while might have seen, the 2018 Wallet Dot Fail talk. This was a well-known talk talking about how to hack various well-known hardware wallets at the time. Now, of course, the space has, evolved a bit since then, but, Dmitry joins me to share some of his expertise This and what he's doing. He has a PhD in chip security and he is doing audits, from a security perspective, and so I think he has some interesting perspectives to share on Bitcoin hardware wallets, such as how much it costs to attack, what are some realistic attacks, as well as, some ideas on backups and Shamir's secret sharing. So check out this episode with Dmitry."
    },
    {
      "speaker": "stephan",
      "time": "01:05",
      "start": 65.2,
      "text": "Dmitry, welcome to the show."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:08",
      "start": 67.5,
      "text": "Hey, Stefan. Thanks for having me."
    },
    {
      "speaker": "stephan",
      "time": "01:10",
      "start": 70.23,
      "text": "So, Dmitry, I know you come from a background of, a PhD in chip security and, you were involved, back in 2018, I believe it was, the wallet dot fail, and so, Thought it'd be interesting to get you on, talk about, to get your thoughts on, Bitcoin hardware security, and I know you've also got a backups project that we'll get into as well. But, just for listeners who don't know you, tell us a little bit about your background and how you got into all this, Bitcoin security stuff."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:39",
      "start": 98.82,
      "text": "Yeah, for sure. So, my name is Dmitry, better known as, Nedospasov in whatever h-hacker, cryptocurrency circles. so, you guys can find"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:53",
      "start": 113.09,
      "text": "My last name N E D O S. so yeah, I did my PhD at TU Berlin in Germany in chip security. I was looking at, you know, the kinds of attacks that you would apply to chips that are coming out nowadays. So think, eAL6 plus certified smart cards, what kind of attacks could you still try to pull off there? what kind of attacks, could you do against something like a modern, smartphone SOC and all that kind of stuff? So that was, that was primarily what my PhD focused on. It's a super niche thing. I mean, there's probably, I don't know, I would say less than a hundred people in the world that, look at, chip security at the kind of level that, that I do. So it's, it's totally a niche market, i-in the sense that there's just not a whole lot of people, doing this at a professional level. And, yeah, right when I was about to finish my PhD, I think it was twenty fifteen, twenty sixteen was when, the Trésor Gonna get into crypto a little bit, I was just immediately triggered, you know, zoom focused in on, on this, just, just completely mind blown that, I, I mean, for all intents and purposes, I mean, the promise of, the hardware components, et cetera, that the Trezor was gonna use, I thought were gonna be a little bit inadequate for storing, you know, millions of dollars of crypto. I mean, I had a lot of conversations back then, with, essentially, I mean, one professional like I am, over the years we actually did a lot of white label research where, essentially we do research, a company publishes it, I mean, quote unquote, as research that they did internally. I mean, I don't have any bad feelings about that, but, I mean, the, the is, is just something that you do. And so I remember going to the office of a company that we were working with, at the time, and I was pitching them this idea, like, let's look at all these, I had a bunch Let's take a look at them, we're gonna find, you know, big issues with, all of these. And they were like, I mean, I just remember the quote, the, the kind of the manager, the head, the head making the decision said, \"Who's gonna be storing more than a couple thousand dollars on, on these, hardware wallets?\" and I was like, \"You don't understand, it's going up in price over time. These same people that are putting, a thousand dollars on them today are gonna Right over time, but that was definitely, one of the things that piqued, my interest was just when hardware wallets started coming out, 'cause it's like a, a very interesting application for the, you know, the unique skill set, that, I kind of did my PhD in, et cetera."
    },
    {
      "speaker": "stephan",
      "time": "04:39",
      "start": 279.37,
      "text": "Yeah. So As you said, the value rose so dramatically, and that is now starting to put Bitcoin security into a, into a new category, right? And if, and if, you know, let's say we're all bullish on Bitcoin, obviously I'm bullish on Bitcoin, I presume you are also. Yeah, yeah, totally. It's only gonna become more important and more valuable, for these things to be, you know, for our coin to be secured in a good way. Now, Do you wanna just provide a little bit of an overview on, you know, where we are today, just generally, like abstracting away from just Bitcoin security, when it comes to, you know, smartphones, and I don't know, there are other, you know, high security applications that are out there. Right. Do you mind just expelling out a little bit of where Bitcoin is today versus some of those other applications?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "05:32",
      "start": 332.36,
      "text": "Oh, totally. I mean, that's a, it's kind of a good place to start, I would say. So the, the-- I mean, in general, if you look at kind of, and I, I think, in pass-- I mean, can we, can we let the podcast know you came over, and I showed you dumping, Trizor, in person?"
    },
    {
      "speaker": "stephan",
      "time": "05:48",
      "start": 348.23,
      "text": "Yeah, sure, sure."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "05:50",
      "start": 349.77,
      "text": "All right, fine. So, I mean, he, yeah, Stefan can vouch for it. He saw, he saw it in But yeah, but if you look at, if you compare like a cryptocurrency wallet to what you would have, say, I mean, the kind of pinnacle, ironically, over, over time or, or in history was smart card security, and there's actually a really, good book, which I also, I think I mentioned to you, Stefan, is called \"Murdoch's Pirates,\" which, is basically about the hacking that happened in the nineties and early two thousands, where, essentially the different companies, doing, Making the card that you put in your Direct TV receiver to be able to decode, and it's usually like decode the next five seconds of, TV, that's how often they switch keys, for the, for the encoding. the, the security of this smart card, basically what ended up happening was like, and it's all detailed in this book, was through shady structures, all of these, all the companies were hacking each other and hiring, subsidiaries to hack their competitors and then, leaking the keys of their competitors to Pirates and stuff like this, so there, the people don't understand that there's already a, a precedent for, like as, as soon as there was, you know, financial, billions of dollars or like millions of dollars of financial gain, all the complexity of we have to go to, Scanning electron microscope or focused ion beam level, reverse engineering at a transistor level of these chips, there's already precedents for this having happened before, completely, you know, not affiliated with the government or anything like that. I mean, the government, will be like, another thing that's, that's coming into, to the purview, so to say, right now. I mean, the, I, I think I mentioned to you that the IRS had a, had essentially a tender, for companies to recover,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "07:49",
      "start": 469.01,
      "text": "aren't aren't aware of that they actually had, a bidding process where companies were bidding on, you know, claiming that they have the ability to recover cryptocurrency wallets for the IRS, which, I mean, hint, hint, I think that means the IRS has thousands of, wallets if they're, if they're, you know, trying to get, trying to get a bidding process, going. So, I mean, there's kind of these, private actors, there's, you know, the public sector, quote unquote, Level of security is night and day when you look at smart cards, you know, there's, obfuscation, they do custom chips per, customer, they do crazy amounts of lengths that they go to, and so everything that you'll see in, cryptocurrency, it's very much, you know, open source general purpose, which I totally-- I mean, I'm a huge, fan of, you know, the open source, part of it, you know, the community coming together to build these things, but there's just a gigantic gap at And, essentially other industries and, and, the kind of security that you would see on, you know, most hardware, the popular hardware wallets today, I mean, some of the-- I, I have to admit that we also, one thing that I forgot to mention is a-- after we did our talk, I mean, we should get into the talk, as well and some of the feedback. I mean, I just remember, for a long time I wasn't doing any public interviews or anything just because of, the, the outrage on"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "09:19",
      "start": 558.99,
      "text": "Time, to, to s- let that all sink in, and kind of feel that, you know, you can, you can go back to the opinion that you previously held on, on a lot of these things and, and continue, the discussion. Yeah. But, so, so let's stay focused on the,"
    },
    {
      "speaker": "stephan",
      "time": "09:32",
      "start": 572.34,
      "text": "yeah, we'll, we'll, let's, let's talk about, you know, the, the different types of devices and kind"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "09:39",
      "start": 579.11,
      "text": "of where, right. So, I mean, you know, I, I mean, in Various, devices sort of, I mean, I usually summarize it as, you know, USB stick slash encrypted, USB stick level of security. there's some, companies that use, like a true, smart card based, chip. I mean, so you could argue, you know, that's, for example, Ledger on the Nano S, use essentially a smart card based secure element. the, the one that gets used, by a lot of companies, is actually the, Microchip ATCC six o eight, and there's also like the Maxim, I mean, both of which are on the Coldcard, for example. I mean, those are technically, I would call them authentication, ICs if I wanna be, really picky, because they're not actually executing any code. But for me, that's like a, an important line, whether this thing has code running on it or it's just some sort of state machine. and then actually, when you get into, crypto for backend stuff, I mean, I, I"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "10:49",
      "start": 649.09,
      "text": "So somebody like Swan is probably running, a hardware security, module, an HSM, on the backend, where essentially in a separate environment they're, running and signing and, and doing all this stuff. So, I mean, there's issues with, every, every single one of those. I mean, maybe the most, obvious ones if we're starting from the, from kind of from the tail end, in the HSMs, I mean, a lot of the crypto that gets used in cryptocurrency, I mean, I know we're But especially if you go, you know, into anything outside of Bitcoin, it's kind of-- I always say it's like the cyberpunk, or the cipher-funk, cipher, cipher-punk, dream cryptocurrency, 'cause, it's essentially the, you know, you, you'll have a, a process in which the next algorithm gets selected, and the number two algorithm, so the number one loser is, the one that gets picked for a lot of cryptocurrencies, which, I mean- That's not to denigrate that algorithm, in any way, but, what ends up happening is that algorithm didn't make it in a certification, and that means that, out of the box HSM doesn't support it. So, when we're talking about HSM, the gigantic problem is how much of the cryptography that has to happen to support the cryptocurrency is actually happening on the HSM versus, you know, being written as custom third-party libraries that no one ever looked at and then running on the HSM. At which point, it's a question of security benefit from having an HSM at all, for example. So, I mean, we have this argument with a lot of, consulting clients, et cetera, et cetera. So, I mean, that's the kind of the HSM example. Yeah. Go ahead."
    },
    {
      "speaker": "stephan",
      "time": "12:26",
      "start": 745.57,
      "text": "Gotcha. So when you mentioned, the curve, like, are you referring there to like Libsack P two fifty-six, two fifty-six K one or what? Yeah."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "12:34",
      "start": 753.8,
      "text": "Yeah, exactly. So, I mean, it really depends 'cause,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "12:44",
      "start": 764.22,
      "text": "Include them anyway, but there's a lot of, p-- I mean, for example, the curve, they use a different curve. That's a game over if the curve's not included, it's not running in the, in the hardware, so to say. If it's not running in the hardware, I mean, can you claim that, you know, this hardware security module that's supposed to be doing all the crypto in hardware is, you know, fulfilling, its promises to you as, as the, you know, the integrator who's using"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "13:15",
      "start": 794.58,
      "text": "Questionable, click, click, click on doubt."
    },
    {
      "speaker": "stephan",
      "time": "13:19",
      "start": 798.75,
      "text": "Yeah. Okay. and so just, I guess, just to close out the loop on the different device types, so you mentioned like the, the Pay TV example of like being a very high level of security, at least compared to what's out there today, where would you put, you know, smartphones? Like, Google has the, you know, Pixel, the Titan chip or Samsung, you know, there's different smartphone level of security, Where would you put that?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "13:47",
      "start": 827.07,
      "text": "I mean, another metric that I often use, so, I mean, when the, when the, so like before the pandemic, one of the things that we would do is we would fly to companies, give trainings. I mean, so for example, I did a training for the, essentially the Android slash, Titan team at Google one year, just before the pandemic, I mean, I've been at companies like Airbus, at their facility in Toulouse, et cetera, et cetera. So, Or, do these companies have, working on something? And you will find that somebody like, you know, the, a Titan team or something along those lines has, you know, for sure, especially s-- compared to a smaller, smart or a smaller, hardware wallet manufacturer, I mean, they will have more security engineers just on the security chip. They probably have, you know, tens of people working in security in total, but they probably have more people working in- on the essentially the secure element portion of it, the Titan chip or something like this, then, a hardware man- manufacturer has engineers. So, I mean, I, I think the people that, you know, just rubber stamp and say that you can't trust, a smartphone or a mobile phone, you know, just flat, flat out, you can't trust it, it can't be trusted because, you know, you can use it for surfing inappropriate websites or so, stuff like this, they're kind of, missing the forest from the trees. I mean, Pretty far in terms of, overall security, you know, if you have, for example, a separate smartphone, that you just have offline, the entire time."
    },
    {
      "speaker": "stephan",
      "time": "15:24",
      "start": 924.23,
      "text": "I see, yeah. And so how much, so I mean, in the, let's say, Bitcoin security world, actually, before we get into that, let's, discuss a little bit about the wallet dot fail stuff. So, you know, this is kind of, I guess- This is maybe your public entry into the world of Bitcoin security, so do you wanna just tell us a little bit about what happened there and sort of, you know, back in twenty eighteen, I believe it was, and then sort of where things are at now? Yeah,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "15:54",
      "start": 954.26,
      "text": "exactly. Yeah, I mean, it was actually a, I mean, I remember,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "16:00",
      "start": 960.47,
      "text": "I, I was actually when, when, I mean, when you were in Dubai, I was in Dubai and, we wanted, I wanted to meet up with you, and I went back to my Twitter back in the day. So, I mean, a long, long, time ago. but yeah, no, it was, it was, it was pretty crazy. I mean, so, like I don't wanna-- I mean, for, for us, it was great. I mean, we, I mean, ever since then, we've been, essentially auditing, every wallet. I mean, so that totally-- it did put us on the map. I mean, people, people totally find us. I mean, people who want an external"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "16:42",
      "start": 1001.62,
      "text": "The leader, I mean, we're probably looked at the most wallets out of, anyone in the, in the world, just the amount of audits that we do. Not all of them get published, by the way. I mean, 'cause people ask us like, \"Uh, you only have, you know, a handful of, of public audits, we do a lot of private ones, as well.\" but yeah, I mean, the, the, the talk itself, I mean, we did"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "17:03",
      "start": 1022.69,
      "text": "the talk, I mean, I, you know, like Security, infosec scene, you know, it was, it was objectively a good talk. I still get fist bumps from, everyone who saw that talk, back in the day. But, a lot of people in, in crypto, took it as like some personal, personal thing that we had some sort of, vendetta, to go out and, and, you know, publicly shame, the hardware wallets, and that totally, that totally wasn't it. It was more to start, you Have people be cognizant of the fact that, you know, a lot of the, a lot of the things that your hardware wallet says, I mean, at the end of the day, a lot of it is also marketing driven, the words that they pick on their, you know, public, on their public pages, et cetera. I mean, it makes a lot of sense to, to have, an independent third party, look at these. And I think, I mean, whether it's, the issues that"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "18:12",
      "start": 1091.68,
      "text": "Take a look at it, we would have identified all these issues, you know, before the product launch or, or something along, those lines. So, but I mean, I vividly, I vividly just remember that we did a talk, there was a, a kind of a, you know, an incident response post, I mean, Pavel, got up in the, on, in the, he was in the first row to ask the first question, you know, to us, in the talk,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "18:42",
      "start": 1121.64,
      "text": "Claimed that we did, James Bond movie style hacking of, of the ledger and that none of this transfers into reality, which I have a little bit of a, a bone to pick with, that statement, 'cause it was, completely, trans- transferable. but yeah, but I mean, so for example, I mean, the, basically, I mean, there was, there was like a, a, a big discussion on, you know, the, the, the part that made me a little The ledger and the Trezor, and we showed vulnerabilities in both, which were, you know, pretty big issues. And then the Trezor Reddit was like, \"Can you believe these issues in Ledger?\" And the Ledger Reddit was like, \"Can you believe these issues in Trezor?\" And it's like, \"Guys, did you--\" The talk was about hardware wallets in general and the issues that, creep up from using, hardware wallet and blindly trusting it and all this kind of stuff. And then, I mean, it was totally, it was totally"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "19:42",
      "start": 1181.9,
      "text": "I don't know what, what color you pick versus Team Blue, but at the time, at least, I, I think Ledger had a blue logo back then. I, I guess Trezor would be green, but, they were totally bashing, bashing each other, on Reddit, and totally missing, missing the overall point of the talk, which was, you know, I mean, the, the kind of the overall point of the talk was the hardware wallets were designed primarily like the feature that all of them, absolutely tick the checkbox for is they"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "20:12",
      "start": 1211.62,
      "text": "Affected with malware and, it's sending all the crypto. That's, that's absolutely the issue that all of them solve, one hundred percent. But, to claim that this is the best way, you know, from now until eternity to have your funds on, it really depends on your use case, it really depends on how you're storing it, where you're storing it, et cetera, et cetera."
    },
    {
      "speaker": "stephan",
      "time": "20:31",
      "start": 1231.08,
      "text": "Yeah. Okay. So I guess the next question would be, you know, from 2018 to here we are today, April 2024, how much improvement has there been? Like, how far have hardware wallets come in that time?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "20:45",
      "start": 1244.75,
      "text": "Well, I, I think a lot of hardware, I mean, so Trezor just launched their Trezor that does have a secure element. I mean, again, waiting, I mean, I, I'd be, we'd be more than happy, if, you know, if Trezor came to us for a public audit, for our feedback, on it. I mean, I haven't had a chance to get my hands on it. I, I know that, I, I know the kind of,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "21:10",
      "start": 1270.19,
      "text": "SE they're that don't have a secure element, what ends up happening is you can essentially dump, all of the, I mean, essentially the demo that I, that we did together, so just for the listeners,"
    },
    {
      "speaker": "stephan",
      "time": "21:26",
      "start": 1286.08,
      "text": "if you could explain. Yeah,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "21:27",
      "start": 1287.02,
      "text": "ju-just for the listeners, I mean, what you can do with a Trizor is you can read out, all of its, contents. Everything is stored on the only chip that is on the Trizor, which is a STM32. You can read out all the contents, then The one change that they did after the wallet fail talk is now they encrypt it, but if you, try to run, I mean, if you write a script to decrypt this, there's one floating around on the Kraken security blog, just FYI, the, the, you can use that script to, to decrypt the, essentially the, even the encrypted ones, and you're talking about, you know, ten minutes max to brute force, a, six digit, pin, and if we're talking about, I don't, I Or something along those lines, but at, at the end of the day, you recover the seed phrase, and so that's one of the, that's one of the inherent, issues, with, hardware wallets, I mean, the standard way that we see all hardware wallets do it, which is the seed phrase, and literally your words are stored on the hardware wallet as is, and the, they're stored as is because if you use a passphrase, they need to take the words from the seed phrase and add your passphrase on top of it. So they're All the hardware wallets that are storing your, that let you use a passphrase along with them, they're storing your seed phrase as is, as those words somewhere in memory on one of the memories on the hardware wallet. So I mean, that's also true for, for, you know, other wallets that do use a secure element, it's just a question of where is it being stored, what's it encrypted by, is it encrypted by the secure element, is it just encrypted by the pin? If it's just encrypted by the pin, like in the case of Trezor"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "23:14",
      "start": 1394.29,
      "text": "The, the, the passphrase. And I mean, the demo that I gave you was, kind of a older Trésor, so everything up to, one dot seven three wasn't encrypted, so you could just get the seed phrase in plain text, just read it, as it appeared on the screen."
    },
    {
      "speaker": "stephan",
      "time": "23:29",
      "start": 1408.7,
      "text": "Yeah. And as you mentioned, the, the passphrase was, the, let's say, supported or chosen mitigation that the Trezor team came out with afterwards. And so then, I guess that sort of pushed the ball back one step further, because then it was like, okay, well, now you need to make sure you've got a long passphrase, 'cause otherwise that can get easily brute forced. Yeah. Well, I mean, that's actually,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "23:49",
      "start": 1428.59,
      "text": "I, I would disagree that, that, that's actually older, that's pre our talk that they came up with this. It's People are gonna take issue with it, but you, you can read the BIP on the, on the passphrase. I mean, I mean, the, the, like, I, I don't wanna, I, I ju-just a disclaimer really quickly. I, I don't wanna to sound like I'm bashing any one of these, manufacturers. I think, I mean, you know, I, you won't believe what devices we've seen, for example, the Trusor Crypto Library get used in. I mean, you know, s Taproot is totally, I mean, the open source approach, they cornered, you know, they, they were the first, they did it all open source. They're kind of everyone else is standing on the shoulders of these giants that released it all as open source. Like they did a huge contribution to the community. It's all out there, their, overall their firmware quality is, very good. I constantly refer, you know, whether it's other wallets or other embedded, consulting clients, we go-- we send them links to commits to code on Trizor The issue is if the underlying hardware's vulnerable, that doesn't, that doesn't actually help. So from, I mean, to this day, and even, everything that I just described, the, the issue's not in Trésor, the issue's in the STM thirty-two chip. And so they selected the STM thirty-two, the STM thirty-two is vulnerable, you can dump the, you can dump essentially the seed phrase or the encrypted version of the seed phrase, and then you can brute force it, et cetera, online. So it's not technically Bip it is. I mean, so Trezor, by the way, I mean, so Pavel and, and all are the authors of Bip thirty-nine. I mean, people don't, people forget that. So the Trezor founder is the one who, submitted Bip thirty-nine, it got, you know, sucked up into, into Bitcoin. I don't remember which one adds the passphrase, 'cause I'm pretty sure it's not, I don't think it's Bip thirty, it might be Bip thirty-nine, it might be another, like one Essentially, what the, so the idea behind the passphrase was like, let's say we're going out for, I don't know, I re-let, let's say I need, today I need to generate a wallet for Stefan and I want him to not see all the addresses that he's using, so I'll just use my seed phrase, I'll add Stefan on top of it, he'll never be able to back, you know, back compute, figure out what the original seed phrase was, and now I can give him a new address,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "26:22",
      "start": 1581.55,
      "text": "created in any way with the seed phrase that I use, primarily without, revealing it. So that, that was kind of the intent of it, and it grew, the fact that it grew into like a security mechanism. So originally it was for you to be able to generate, you know, additional seed phrases without,"
    },
    {
      "speaker": "stephan",
      "time": "26:37",
      "start": 1597.02,
      "text": "let's say,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "26:38",
      "start": 1597.54,
      "text": "new-- Yeah. Yeah. So, but not just new accounts, essentially, like completely new derivation paths, right, that are in no way affiliated with the original. So I, I would, I would say to co-- say that that is Was a stretch at best. I mean, so it wasn't, it wasn't even, pitched as kind of a security, feature, initially. And then, I mean, we haven't talked about wallet recovery yet, but that's actually one of the, one of the things that, there's a lot of vendors doing where they'll use a GPU farm to essentially brute force, your passphrase on top of your-- So you send them your, you know, you forgot your passphrase, you send them your bip thirty-nine, and they will brute force it for you"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "27:22",
      "start": 1641.59,
      "text": "Crypto they recover, so they're gonna, you know, essentially generate the password check is there money on all the addresses that get derived from this path, and then identify the ones that actually have, money on them, 'cause there's no, there's no other way to check. You essentially have to spin up a full-blown wallet, look at all the addresses, is there anything stored there? Oh, okay, this one has, money stored there, that must have been a passphrase that this user, was using."
    },
    {
      "speaker": "stephan",
      "time": "27:43",
      "start": 1662.7,
      "text": "Yeah, and, listeners, you might be interested, I have an earlier episode with, John Cantrell, who spoke about his process of, brute forcing, and basically the, the situation with John Cantrell is, I think somebody had a competition where they were releasing kind of seed words, and I think once it got to maybe seventh or eighth word out of-- I can't remember the, the exact detail, but John Cantrell went and set up like a GPU farm and kind of computed and found the first address and found the money, and, you know, he- Won the coins. It was a really interesting, story. But I guess coming back to, you know, security and, how it has evolved, yeah, so it seems like as you're saying, the passphrase was not initially pitched as a security feature, but nowadays, there are a lot of people who use it as one, even if it's not, you know, was not intended that way. I mean, I, I don't,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "28:33",
      "start": 1713.23,
      "text": "I, I would say, I, I only have, so I mean, there is still a"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "28:42",
      "start": 1721.94,
      "text": "In addition to bit thirty nine, I would argue so. and I don't-- I mean, so me personally, I, I don't know all that many people that use, passphrase. I, I don't think it's, I mean, I would argue you shouldn't have to use a passphrase. I mean, it should be, it should be secure as is without the passphrase."
    },
    {
      "speaker": "stephan",
      "time": "28:59",
      "start": 1739.24,
      "text": "Yeah. Okay. Well, let's bring it to, you know, hardware in general, like Bitcoin hardware in general. Like, as you were saying, the main thing that we could say about most of these Bitcoin hardware devices, signing devices, or hardware wallets, whatever you wanna call them, the idea is that you are separating them from the, the online connected computer, right? Like, that's where people have this concept of hot wallet and cold wallet And the idea is that this is your, this should theoretically be your cold wallet. And so that's the main thing you were saying that they get right, but the part that maybe, you know, where it, it's more, you know, that's where some of your work comes into play is if the attacker has physical access to the device You know, can they poen it? And importantly, how many, how much reso- how much in resources do they need to spend to poen it? How much time do they need to poen it? Is that kind of where the debate is? No,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "29:54",
      "start": 1793.75,
      "text": "totally. I mean, you, you nailed it. So I mean, it's a, it's a question of, so I, I think what a lot of people, and this is like, issue, I mean, I, I remember going back to even my, I mean, the typical thing just"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "30:13",
      "start": 1812.88,
      "text": "We'll discuss here in a second, that, people use is how much equipment do I need, and then like, let's say that the cost of the equipment is the cost of the attack But that's not really representative, because if you're running this as a business, I mean, you're gonna buy the equipment once, and then it's a question of how many, how many times do you end up, using it? So that, that's not really a good metric. that being said, I mean, on the Trizor, you're talking about, you know, you, you can, on the original Trizor slash Trizor T, we're talking about, you know, very little hardware. I mean, we actually-- so, I"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "30:53",
      "start": 1853.45,
      "text": "What I was also showing you using an FPJ board, which can cost anywhere from, you know, twenty to a hundred dollars, I mean, you can also, in theory, I mean, some people always give me crap 'cause they're like, \"You can use a Raspberry Pi Pico, which is like a ten dollar board,\" I mean, you could, or, I mean, I know that FPJ is gonna work, so I usually use the, the FPJ just 'cause that's my, background, but, I mean, we're talking about hundreds of"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "31:22",
      "start": 1882.14,
      "text": "Sorry. So if you, if you look, for example, Ledger did, a couple, publications on, I mean, so this is like another thing which, you know, also, you know, In terms of, you know, I, I'm glad we don't have a wallet that we're kind of an independent third party. I, I feel it gives us, a little bit more leeway to say this stuff, independently. But for example, Ledger has a couple publications at, probably the, you know, the biggest, most notable, hacker, security conference, which is Black Hat in Las Vegas, and, they were essentially looking at the six o eight, kind of with the, with the target in their sights,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "32:04",
      "start": 1923.57,
      "text": "I mean, there they were adding essentially instead of just using voltage glitching, which means you have a power supply and something to turn the power supply on and off really quickly, now you're talking about adding a laser to it, and probably to add the laser to it, now you're talking about at least having, you know, some form of chemical lab or something there, to actually open up the chips. And so, I mean, some would argue the calculation there is, what does a chemical lab cost, plus what does a laser cost,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "32:32",
      "start": 1952.01,
      "text": "plus what is, you That you have to have in a room while the lasers on, cost, you have to add all those up and then that's the cost of the attack. but, it's r-really, I, I think the more, the better price, would be, to split it into like R&D cost and then incremental, cost. a lot of times these, especially when we're talking about, you know, anything having to do with, reverse-engineered chips or open-up chips, I mean, I know at you can just go to the professor and say, \"Hey, we're a private company based in Germany or wherever, we wanna come in, can we rent the lab for a week?\" And they'll be more than happy 'cause they're, they're like, \"Sweet, we're gonna buy, I don't know, books or-- I mean, whatever. Whatever our university buys, we're gonna buy new equipment. somebody's gonna pay for the lab.\" And a lo- a lot of times when you get into really expensive equipment, they're actually extra interested in this because Use, the less time they'll have to spend on calibrating the equipment when it goes out of-- because basically by using it, you're making sure that it's working, and so it'll save them time when they wanna come back to it, they won't have to be recalibrating every piece of equipment in the, in the lab. So, I mean, I, I would say it's, I, I mean, I'm a big fan of, splitting it into essentially like the R&D man hour cost, kind of, approach, plus, Lab times actually required to pull this off. So I would say, you know, if you're talking about the, again, if we're talking about the, Trezor, I mean, effectively it's probably, you know, less than a hundred dollars worth of, worth of effort, for, pulling off these kinds of attacks. If you're talking about something with a secure element like a six o eight, you're already in the thousands of dollars, and there it really depends on the wallet, 'cause, I mean, this is Implementation, so they could be super vulnerable or they could be less vulnerable, and it really has, it's a question of how do they use the secure element, how many chips do they have, do they have two secure elements, do they have one secure element, how are they, speaking to one another, so it's hard to kind of do a blanket statement there. but m-most likely, I mean, I, I would say thousands to tens of thousands of, dollars, and then if you're talking about something like the, at some point you kind of"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "35:03",
      "start": 2103.45,
      "text": "So if you, if you have to go into the chip and open it up and do, like transistor level modifications, you're talking anywhere from-- I mean, that, that's it. Like at, at that point, you're, you know, if it's a video game, you turn God mode on, you can do whatever you want to the chip. so I mean, that, that's-- there's no going beyond that. there, you're talking about, you know, fifty to a hundred thousand per device of effort. However, I mean, to get to Where are the vulnerabilities? I mean, where, how does the data move? How can I, you know, dump the data that's on there, et cetera, et cetera. So, I mean, you can, you can quickly end up on a chip that has no documentation, no open source firmware. what ends up happening is you're just gonna spend, you know, many, potentially many years of, R&D to get to the point that you can, pull off the attack. So, I mean, that's,"
    },
    {
      "speaker": "stephan",
      "time": "35:58",
      "start": 2158.09,
      "text": "that's,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "36:02",
      "start": 2162.03,
      "text": "that's Open source is great, I mean, and I, I'm a huge supporter of open source, but people need to understand that at the end of the day, especially in these, especially in the consumer product space, there's a lot of security through, obscurity. I mean, if, you know, if- I have a feeling, you know, if, for example, if Ledger open sourced, everything that they have running on their Secure Element, which they'll never do because they're obliged by NDA not to ever release that, but I'm sure people would find, you know, serious security, vulnerabilities just because you would have a, another set of eyes looking at this and it's just somebody coming from a completely different angle, they'd, they'd be able to find something."
    },
    {
      "speaker": "stephan",
      "time": "36:42",
      "start": 2202.22,
      "text": "Back to the show in a moment. This show is brought to you by Swan Dot Com. Swan Dot Com has a mission to onboard millions of people into Bitcoin, and the team have been working really hard to update the Swan Bitcoin app, which you can find in the Google Play Store or on the Apple App Store on your phone. So the team has been working really hard to improve that app, make it really fast for people to sign up and be able to buy Bitcoin, so you can go from zero to Bitcoin in just a few minutes. And so this is a really great way to- To help onboard your friends and family, if, if you're struggling to get them on board, tell them about Swan. And, not just that, Swan is rolling out a new promotion where it's zero fees for your first ten thousand dollars of Bitcoin buys. So you can be standing there with your, you know, with your uncle or whoever, and if they are a no-coiner, you can get them off zero and get them started, and it's zero fees from Swan to buy up to your first ten thousand dollars of Bitcoin, and it's not just for new customers, it's also for existing customers So make sure you check that out, send them over to swan dot com or of course the swan app in the Apple App Store or the Google Play Store. This show also brought to you by mempool dot space. Mempool dot space is the leading Bitcoin and blockchain visualizer. Now, as you know, the halving happened and, all the degenerates are in the mempool with their runes and inscriptions and things. So mempool dot space is an invaluable resource to keep an eye on what's going on. I've, you know, I'm regularly tracking what's happening And see what the fees are like, and of course, whenever I go to send an on-chain transaction, I'm checking mempool dot space, and you should too. Mempool dot space have a range of dashboards, they've got a lightning dashboard, a mining dashboard, they've even got liquid, you can also search Bitcoin transactions, there's so many things you can do, and they're rolling out a mempool transaction accelerator, which you can find over at mempool dot space slash accelerator. And lastly, this show is also brought to you by coinkite dot com, my favorite Bitcoin Creators. Now they have a range of products, they're most known for the Coldcard. This is the Mark IV, of course there are some earlier versions, and their newest product, which is coming out and shipping out to people now, if you pre-ordered, is the Coldcard Q. So they are-- it has a lot of the similar features as the Coldcard Mark IV, but it's also got a QR code, and you can use batteries to power it, so that can be really practical. Let's say you've got your, device in a In a far location, and you need a way to power it. Well, now you can bring triple A batteries and, and charge it that way. So the cool thing about these devices is that you can generate your private keys offline, you can keep the device offline, and there's a range of features that you can use, such as multi-signature to help improve your security level. Now, I wouldn't recommend multi-signature for total beginners. When you're a beginner, I would say just start with a standard hardware wallet, and then over time, you can think about how do I improve my setup over Because, as, my friend NVK, the CEO of CoinKite, says, you've gotta secure your Bitcoin like it's worth ten x what it currently is worth, because Bitcoin can move up really quickly. So, go to coinkite dot com, make sure you get your gear. That's the, the cold card. There are various different devices that you can get there. You can even get the metal seed backup plates, called the seed plate there. So there's a range of things you can get there. Go to coinkite dot com, use code Laverara 'Cause I, I, you know, when you talk to IT people and security people, they often say security by obscurity is a bad thing, but in this case, you're sort of saying it almost, in a certain context, it actually raises the cost or makes it harder to hack that particular, to pwn that particular device."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "40:24",
      "start": 2423.82,
      "text": "Exactly. And I mean, unfortunately, unfortunately, that's the takeaway of the book that I was mentioning before about the P2P industry. It was all of the, essentially, the security that they got to and the, and the level that they got to I got to, and the fact they haven't been hacked has nothing to-- I mean, it has something to do with security, but it's mostly obscurity. I mean, it is like ninety-nine percent obscurity and one percent security engineering on, on top of, what they were doing, but for the most part, it's obscurity."
    },
    {
      "speaker": "stephan",
      "time": "40:52",
      "start": 2451.5,
      "text": "Yeah. And when you mentioned that kind of threshold, let's say the god level or the god tier of fifty thousand to a hundred thousand, would you say that's even in the case of those Pay TV cards, or would you say that's even"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "41:04",
      "start": 2463.99,
      "text": "no, so I would say for, for them, the, the problems, the problems for the PTV is that the R&D is even exponentially higher, than, than it wouldn't be for- Right. It's not just the kind"
    },
    {
      "speaker": "stephan",
      "time": "41:13",
      "start": 2473.38,
      "text": "of material cost of the labs and whatever, it's actually the R&D cost would be more prohibitive there on that side. Yeah. Yeah. And,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "41:20",
      "start": 2479.68,
      "text": "and, and I mean, if we're-- I mean, you, you and I-- I know you and I have had this conversation. I mean, another kind of data"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "41:34",
      "start": 2493.55,
      "text": "I mean, the book's just a really good documented, you know, copy of, all these shenanigans that went on. I mean, I'm surprised, some, some, some Australian that wanted to, some young Australian journalist that wanted to write, you know, a book about, Rupert Murdoch shenanigans picked, picked this story 'cause it's a pretty epic one to, to pick up. but, the, the-- I mean, yeah, the, the one thing, that people also kind of lose Likely are you to have to reverse engineer that exact chip or is there the possibility that I can go and look at a number, another member of the family, to essentially get a lot of, insight? So, I mean, I, even though I, I would say, I mean, just as an example for the purposes of the discussion, everything that you can do, on the STM32 carries over to all the members of the STM32 family, 'cause at the end of the day, they're based on the same ARM Cortex-M cores. They have the same, kind of, you know, circuitry, that handles them booting up, et cetera, et cetera. And so, there-- I mean, there are differences between them, but they're, they're still members of the same family. They, they, you know, they walk like a duck and quack like a duck, they're a duck for the most part. Gotcha. And so you could, you could say the same thing for a lot of the secure-- I mean, a lot of the higher end secure To wallet marketing purposes, calling, the authentication chips that a lot of them use, a secure element. I mean, I, I won't completely fault them for it, I just for the purposes of my technical discussion, for me, a secure element is always something that executes, code, so it has to be essentially a smart card-esque device that, executes code, otherwise I would call it, authentication IC, because then for me, that, that wording implies that it doesn't execute code. If you're talking about a device that executes code A lot of the, so for example, the, the chip that actually gets used, on the ledgers, the, the security chip that they used, at least on the Nano S, I know for a fact, also gets used in printer cartridges. And so printer cartridges, there are, you know, printer cartridges based on this chip where you can go on Amazon and you can buy, you can buy essentially a compatible, printer cartridge chip, you-- that where the original had, its in- So the printer cartridge is essentially authenticating itself to the printer as being authentic, and so there are printer cartridges that use the same family of chip that Ledger uses. And so the question is, if you went to China, and so if you can buy, go on to Amazon and buy a cheap printer cartridge, that means that somebody in China hacked that security chip and dumped, all of its contents and, was able to write from scratch, essentially compatible firmware. So now the question is, can I go to China and figure out who did the work, at- And, you know, would they be willing to share this information with me, to save me a ton of R&D and, essentially get to, get to from point A to point B in a fraction of the time and for a fraction of the cost? 'Cause, I mean, we're, we're not, you know, m-me as an outsider looking at cryptocurrency wallets, I'm not trying to encroach on their, on their boondoggle, on HP printer cartridges."
    },
    {
      "speaker": "stephan",
      "time": "44:58",
      "start": 2698.23,
      "text": "Okay. and so I guess one other, I guess, practical consideration, thinking back to my conversations with someone like Michael Flaxman, he, he would sort of explain it like, okay, well, what you can do in practice is use multi-signature, keep the devices in different locations, use different device types, such that you are, you know, for se-- for securing serious amount of coin, that way you're sort of really making it hard for an attacker, because now they've got to- You know, get you in one place, take you to another place, get that other device, find a way to hack that particular different device. So what are your thoughts on that as an approach of using different devices and in a multi-signature configuration?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "45:42",
      "start": 2741.61,
      "text": "So it totally, I mean, multisig totally solves this for the most part. I mean, I would argue, you know, how many of the wallet manufacturers are pushing multisig? I, I think that's like a, I mean, 'cause it, it is a solution, but I, I don't think, I mean, from the wallet manufacturer point of view, they, they would claim, you know, the wallet is secure as a single device, you shouldn't worry about it, et cetera. but I agree, I mean- By physically, I mean essentially, either by physically separating the key material or requiring you to sign with multiple keys, this solves the issue. I mean, at that point you can, you know, I like, I'm a huge fan of The stuff that Swan does, I mean, there's other companies as well that do similar, multisig stuff. I mean, it can be, it can be a problem. I mean, I can tell you that, so maybe we can talk a little bit about, recovery as well. I mean, without, without naming, this, this, story, we actually, I mean, without going into all the, all the background, I mean, we actually helped a client who was using multisig, and ended up in the situation"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "46:50",
      "start": 2809.8,
      "text": "Pin on both and forgot the pin. And so now the question was, you know, he has a backup provider, a non-custodial multisig provider that can vouch for him, but he ne- he wants to recover, his, his crypto, and now he needs help with it because he used the same pin, he forgot his pin, he used the wrong pin, he can't do anything. And so now the question is, what do you do? And so the answer was, in this case, we helped him dump the trésor, and then he,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "47:20",
      "start": 2839.82,
      "text": "Which was enough to access this multisig, which was enough to, to access this, funds. So, I mean, all of that is to say, all, all of these are trade-offs and, kind of benefits and all that kind of stuff. another case, similar, similar one that I heard about recently from, from a company that, you know, recently I got in contacted or got in touch with, was that they actually had a case where they had, an, an estate attorney, contact them and the case there was Essentially a ledger blue that was end of life'd, and so now they just can't-- they have this ledger blue, they know the PIN and the passphrase and everything, but they can't, access the funds because it's been end of life'd, and Ledger just doesn't have any support, for this anymore. And so the question was, \"What do-- what does somebody like that do?\" Though, I mean, the, the one, you know, argument that I'll make and kind of, you know- I, I think people should be aware of is implicit. So I, I have to say with the Coldcard and with, for example, the Trezor, I mean, the fact that they actually provide libraries for you to use them completely offline is a huge benefit, where, you know, you can do command line, send the transaction, get the signature, et cetera. I have more confidence in, in those devices, but essentially if you're buying, a wallet to a certain degree, you know, you're hedging your bets on this company being around the Cover your wallet because if, if, what happens is, you know, it is making API calls to their backend to, announce the transaction or get a snapshot of the blockchain, and that's the only way that it's gonna communicate. I mean, you might be in the situation where you, you know, you have hundreds of thousands of dollars on this thing, and you can't get 'em off of there because, the company shut down."
    },
    {
      "speaker": "stephan",
      "time": "49:04",
      "start": 2944.14,
      "text": "Right, and so I guess that's also why, you know, it, it, it's cool if you can use third-party software, right? Like the likes of Sparrow, Inspector, and Nontouch, and these other ones, so that way you're not, you're not beholden, you're not sort of vendor lock-in, you know, you have to use this hardware wallet with that particular- Software, that's another angle of it. one other thing, just kind of broadly while we're talking about hardware attacks, as I'm aware, there's different kinds of attacks, right? So one I guess there's a broad category which people call side channel attacks, and that's-- I'm sorry, you're obviously you're familiar with this, but what are some of the broad categories, right? Is it side channel attacks and just kind of directly trying to, you know, take the device apart and open it? What are some of the different categories here and things to think about there?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "49:54",
      "start": 2994.38,
      "text": "Yeah, so I mean, usually, so, like this again, is, where I, I feel like, you know, I, I can, I can recall my PhD defense, standing and having these arguments with the professor standing across from me because this is completely, you know, conjecture slash opinion, my personal opinion. So I would argue most of the time if you're talking about side channel attacks, that's kind of a implementation, specific thing, so it What crypto algorithm am I using? How am I using the key? you know, what kind of countermeasures am I using? a lot, a lot of times there was actually, patents, from, essentially, so a lot of the patents around side channel attacks and side channel analysis, they're actually from like, roughly ninety-six to ninety-nine to like two thousand. So, interestingly enough, people forget this, that means that all those patents have expired, so, there's like no reason, Pay, any sort of crazy, licensing to, to implement, this kind of stuff. And actually, I mean, I have to say for, for some of this stuff, Trezor actually, you know, has, pretty good-- the Trezor code base has some good examples of what to do, you know, kind of the pin hardening and how they increment the pin counters and stuff like this. They, they have a lot of industry best practices, implemented in their code. I'll give 'em a, a fist bump"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "51:16",
      "start": 3075.63,
      "text": "on,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "51:21",
      "start": 3081.19,
      "text": "Really depends on the implementation, so there you have to have knowledge of what's the implementation, you know, what am I doing? It's also, if you have some idea that there's crypto happening, it might be easier to, make some assumptions about what crypto is happening on this device. So let's say, you know, it's, it's using some standard cryptocurrency curve, you know, the curve, now you can, kind of, you know, create an attack around the fact that you know that if the, you know, when you plug this It's doing some form of authentication and it's using this cryptocurrency, or this cryptography algorithm, I might be able to build a side channel attack against it. The issue, is, I mean, yeah, the, I mean, i-it's, it's possible, I would argue it's a little bit tedious. It's kind of, at the same time, it takes a lot of, prep and, I mean, I-- So I, I'm building up to the point I've never ever done, like a real side channel attack I've totally done 'em, you know, as part of, you know, PhD level, courses and, taught 'em to our, grad level, students at the university, they would all get to do some, side channel attacks. I've never had to do a side channel attack on anything in practice of any device that I've ever looked at, and the kind of the reason for that is, is the next step up is what's called fault injection attacks. And so there, you again are making assumptions about, what kind of code Confident that you can essentially flip, certain values, that are being read as they're being executed, and that allows you to skip instructions, flip certain values from, you know, let's say you have a value of one, you can turn it into a zero. And so if you just think about how you normally write code with ifs and else's, you can easily end up in a situation where, you know, you're executing this code, but now, you fall through, and even though you didn't enter the password correctly, essentially, The glitch turned a one and a zero, and so now, the code acts as if you entered the password correctly, something along this line. So that's generally the attack, the more, kind of, the more powerful attack. And I would argue, even if you're talking about opening up chips and going to the transistor level, usually what ends up happening there is you identify, where's the databus, and you are just injecting ones and zeros, directly onto, essentially, directly into the CPU registers, directly on the databuses as they're flowing there. So it's effectively like you're doing a fault injection attack where you have a hundred percent success rate because you're directly inside the CPU. So you're flipping, you're flipping values, directly, you know, as if you're doing, you know, an operation on the brain of the, of this chip"
    },
    {
      "speaker": "stephan",
      "time": "54:07",
      "start": 3247.29,
      "text": "I see. Interesting. So it's kind of like, even though occasionally we might see news articles about these kind of crazy side channel attacks where maybe, you know, the way I'm typing onto my keyboard and the different keys make a different sound, and therefore from hearing the, you know, someone can like work out what my passphrase is from, like, what you're saying is in practice, actually it's more about the fault injection style of attack as opposed to side channel attacks where people are like figuring out you're typing from the keyboard or the, some of the, you know, some of the Well,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "54:37",
      "start": 3277.13,
      "text": "I mean, so I, I would say like the question is, how likely are you to end up in a scenario where somebody can see you type something in versus how likely are you to, you know, leave your, cryptocurrency wallet at the-- Right. Yeah. Right. I mean, at the airport, like at security in the one of the bins. I mean, I recently left the phone, had to walk back, all that kind of stuff. I mean, just misplace it or evil-mate attacks, I mean, they're called that for a reason. The thing that I would do for, entertainment purposes at cryptocurrency conferences, I would go around and then I would introduce myself and explain all the stuff that I did, and I mean, a lot of people know the talk to this day, so, I mean, I'm, I'm always happy. And then I would just ask people next, I would say, \"Do you have your hardware wallet with you?\" And then you just see people's faces turn pale because you will be absolutely blown away how many people travel with all their crypto on them on a hardware wallet. I mean, it is Practices, I mean, I know you're one of the advocates for how not to do this, but you will be abs- I mean, you know, twenty forty nine is happening in Dubai right now. I mean, you, you don't wanna know how many billions of dollars are walking around the halls there."
    },
    {
      "speaker": "stephan",
      "time": "55:51",
      "start": 3351.02,
      "text": "Yeah, I'm, honestly, I'm very surprised about this kind of thing as well. Like, I've heard of this kind of thing, and I'm just blown away when I hear people do this kind of thing. I mean, maybe they would argue and say, \"Look, I'm a digital nomad, and I don't have a place to leave it or some-- I, I don't know.\" But, yeah, it's, it's, it's always been a bit bizarre to me, let's just say. but, yeah. So I mean, I guess kind of to sort of close off this topic, I guess, do you have any tips for people out there when they are, you know, trying to secure their coins in terms of how they should assess hardware wallets, how should they think about, you know, their hardware security?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "56:38",
      "start": 3398.11,
      "text": "Yeah, so I mean, I think there's a lot of reasons to use a hardware wallet, but you should just be cognizant of like the reasons when it makes sense to use a hardware wallet and when it doesn't make sense to use a hardware wallet. I mean, me personally, we get paid for consulting work, in crypto by some wallets, they'll pay us in, you know, token or they'll pay us in USDT. Unfortunately, I mean, we've yet to get paid in Bitcoin for any audits. I mean, we had this conversation with you, as well"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "57:07",
      "start": 3426.81,
      "text": "And crypto, I mean, I, I can't speak for my colleague Josh that, does, does this, but, you know, for, for the most part, I'm trying to pay the bills, with this, so I'm just taking that money, converting it to fiat, feeding the family and all that kind of stuff. So I, I don't really have a use case just from that transaction alone. I don't really have the use case for a hardware wallet 'cause the time of, life, of the, of the for crypto that I store, I store it, I'm, I'm like, I don't do any trading, so I'm a long-term, hodler, so to say, so, and I, I mean, I, I would anecdotally say that's a lot of users out there, and so I would encourage you to consider, whether you need a hardware wallet at all in that case, because, you might just need the, you know, the seed phrase backup just to delete it, from whatever device you"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "58:07",
      "start": 3486.81,
      "text": "Advocates of, potentially for those kinds of use cases, I mean, people, you know, people easily, without thinking about it, will upgrade their phone every year. I mean, instead of giving your, your last year's iPhone, to your family, why not use that as your new, you know, offline, smartphone, with whatever one, two years of security, via Apple, is worth, just storing, in a, essentially a smartphone app or in a password manager or something Something like that, or even for all intents purposes as a, like an offline note of some sort where you don't have an account or anything, activated on this thing, you could be storing your, your passphrase there and, be leveraging the security that Apple built into the iPhone, for you. but the, the place where it really does make sense to use a hardware wallet, I mean, so the first one which I think is like undervalued is, so for example- We have some cryptocurrency wallets that we look at where they're, you know, there's a gigantic community around them, people are using them, people are like, I don't know, you get into, you get into, you get free drinks at the bar at some crypto conference because you have this wallet, because they're sponsoring an event. I mean, obviously get the wallet, to be part of the community, to be part of that. I'm not saying like crypto, wallets don't, or hardware wallets don't, don't have a, don't have a kind of I mean, they totally do. The other one that's actually, that I, I think if you're doing trading on, on a day-to-day basis, it makes a lot of sense to have a hardware wallet as well. But, just to give you, I mean, like the use cases where it's crazy to me, I know a lot of people are using hardware wallets, that I've heard multiple times is, for example, hedge funds trading on Wall Street trading crypto. I mean, I've heard this multiple times, I'm Up there, is the, the process is usually that they have, cryptocurrency wallet, and they're essentially, they're coming into the office, they get handed, essentially a ledger because that one, in that decision-making cycle, that that's the one that they wanna use, and they, they get handed a ledger every morning from the IT guy. They go, they know, everyone knows the pin to every ledger, so it's that, that issue's solved because the pins the same on all of them generally. And then they go connected to, their Send all the funds that are there to Coinbase Prime or Kraken or whatever they're using to, to trade during the day, and then at the end of the day, they move it back. So, I mean, so many issues, so many issues with that one. I mean, like, I mean, how do you, how much do you trust these guys that are, these traders that are coming in and out? How do you, how do you actually, follow them? I mean, what's the risk of somebody walking out the door with the wallet versus the risk of, Coinbase"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:00:59",
      "start": 3659.71,
      "text": "down on the side of Coinbase, versus the, the guy who has the pen to the ledger and all this kind of stuff. So I, I think the, the gen-- generally though for the regular, you know, listener slash, person in crypto, if they're trading on any sort of regular basis, I totally think it makes sense to have a hardware wallet, especially if you're trading from, you know, your PC, and especially, I mean, the integrations have gotten so good where, I mean, essentially you plug in the Trezor Directly connects, you know, you can do the wallet connect stuff potentially. I mean, the wallet connect stuff will also work with the smartphone app on occasion, but I mean, there's so many, great integrations where I totally see the, the added value of a cryptocurrency wallet versus, you know, restoring, walking around with a piece of paper and restoring it, every single time. So if you're, if you're accessing your crypto on a daily basis, that's when, I think a hardware wallet really makes sense. But if you're, if you're setting up"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:01:56",
      "start": 3716.0,
      "text": "Use that as well, 'cause that's the only real, reliable way to do it. But, use separate pins, guys. Use separate pins. Don't, don't be like the guy that we had help. but, i-if you end up in the situation where- you have, I mean, don't-- I mean, just be cognizant of the fact that the hardware wallets really only protecting you from the machine that you're, connecting to, I guess is, is how I, I put it. I mean, there's, at the end of the day, that's the biggest thing that it's solving for you."
    },
    {
      "speaker": "stephan",
      "time": "01:02:24",
      "start": 3744.89,
      "text": "I see, yeah. And so what would you say about,"
    },
    {
      "speaker": "stephan",
      "time": "01:02:29",
      "start": 3749.8,
      "text": "I think one other thing that hardware wallets can help you on, though, or a few other things, is sort of the practical element of actually signing with that While not exposing your keys online. I think that's the other part that, you know, maybe if you only had it written down or if you only had it on, You know, without a device that can actually sign transactions for you, then how are you gonna actually sign things, right? Like, how-- in, in an airgapped or kind of In a secure way."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:03:04",
      "start": 3784.15,
      "text": "No, for sure. I mean, but I would argue, I, I don't know how much you've used, have you've tried any of the wallet connects stuff on, on a smartphone? I mean, yes, you have two, \"quote unquote,\" internet connected devices, but you're essentially, you know, getting push notifications to your, your smartphone to confirm, transactions. I mean, so they, they solve that for-- it's not just Hardware wallets that can essentially keep you in a semi, you know, offline, environment. I mean, yes, there's an internet connection to send the notification, et cetera. I mean, the, the question is, what's the likelihood if you, so for exa-- I mean, we were, we were talking about, you know, how many networks each of us have before we started recording this and which one we'll be using for the recording. I mean, if you have 'em on two separate networks, et cetera, what's the real, That works. I mean, so the smartphone is the perfect example. I mean, what's the likelihood that if you have this offline device, you put a SIM card in there just to do one transaction, what's the likelihood that in that moment of time, boom, that's when, this device is somehow gonna get owned over the network? I would argue it's pretty It's pretty, remote, but I agree. I mean, a-at the end of the day, you shouldn't be, I mean, i-if you're doing this on a daily basis, if you're dealing with a lot of funds, you should be very cognizant of reducing the amount of time that you have your keys exposed on the same machine that you're using to browse the internet, interact, and money, do all this kind of stuff. That's, that's, there's no question there."
    },
    {
      "speaker": "stephan",
      "time": "01:04:31",
      "start": 3871.23,
      "text": "Yeah. one other question, on hardware wallets, you know, we've been talking about the different, you know, types of security and so on. Where do you see it going longer term? Like, do you see it, you know, as number goes up, as the security requirements rise? What kinds of things do you foresee coming to the Bitcoin hardware security industry?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:04:55",
      "start": 3895.63,
      "text": "I mean, it, it's, it's Difficult to make like, just to completely guess where everything's gonna go, but, there's, I mean, there's, I, I'm feeling, you know, with, if we're just talking about, the crypto economics, I mean, I, I think there's a lot of demand for hardware wallets. I think as, you know, Bitcoin rises, people wanna spend their, their money on things that they can, purchase in Bitcoin. Everyone sells their cryptocurrency wallets for crypto, as well, so that's, I mean, You know, we, I, I didn't really mention it, I mean, I'm sure we'll have like, all the links in the show notes afterwards, but all the audits that we do for Key Labs, I mean, where we do the third party audits for, for people, I can tell you, right now the bull run right now is probably gonna mean that we're gonna have work next year, when, you know, people have, founded a company and started a new wallet and then they'll come to us next year to have it"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:05:59",
      "start": 3959.63,
      "text": "Between, you know, prices hitting an all time high and then, people reaching out. So, I mean, there's definitely room for innovation, but I, I guess overall, the-- if I'm gonna look at the last snapshot, going back to our talk in December 2018 versus, today, I mean, realistically, not all that much has changed. I mean, I, I think the, kind of the formula is, is, sort of, good enough. the kind of the, the potentially depending on, how widespread it is, is kind of the, you know, how cognizant and how much do people wanna defend themselves from kind of the, recovery services, that are, that are out there, nowadays and how much pressure there's gonna be to kind of, protect yourself from, let's say a quote-unquote state actor, or something like that, you know, I mean, if at some point, you know, every, every police department, has, can do this"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:06:59",
      "start": 4019.99,
      "text": "where, you know, people, people might wanna, reach a different level of security there."
    },
    {
      "speaker": "stephan",
      "time": "01:07:06",
      "start": 4026.7,
      "text": "Yeah, I see. so let's turn now to the backups, aspect of it. I know you have a, a solution here that-- I mean, high level, it's, it's, it's using Shamir's secret sharing and NFC tags to kind of make it work, but can you just outline, just overview this for us?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:07:26",
      "start": 4046.32,
      "text": "Yeah, so actually there is a proposal. I mean, so a lot of people, listening to this podcast will know, Ian Coleman and Ian Coleman's lovely website for testing, for testing BIP thirty-nines and seeing how stuff gets derived, et cetera. There is actually a proposal floating for a long time, doing something called Shamir thirty-nine, so it's basically doing Shamir splits, but then converting him, essentially converting him back to, back to words again, and then, so- Converting the splits, or rather taking a seed phrase, splitting it, but then creating words for the splits, which would let you write down, essentially, so if you're doing three splits, you would have three sets of words, that you could then, write down, just using the same, kind of dictionary, just so that you could write them down. It's a little bit different from the slip, proposal that, Trezor uses for their, Shamir, Shamir thing. It's a little bit, The advantage to the Shamir thirty nine approach is that it doesn't, it can actually do it on anything, so it could be a password, or it could be a seed phrase, or it could be, you know, a password and a seed phrase, or, or, sorry, a pa-- a seed phrase with a password, something like that. I mean, it's essentially a technique for encrypting arbitrary data, whereas, the SLIP, one, actually is Bitcoin specific and it also generates, completely different addresses, if you're using it"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:08:54",
      "start": 4134.59,
      "text": "It's less, kind of applicable to, I mean, I, I know you're a Bitcoin podcast, but I mean, for, for us, we try to help people out that do other, cryptocurrencies, you know, Ethereum, what have you, as well. I mean, we're, we're impartial, in that sense. and so the, kind of the proposal is to, to do it like that. So we set up, I mean, I did basically a demo app,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:09:21",
      "start": 4161.51,
      "text": "where, bunch of cards. And where this gets interesting is, actually combining it, because you don't actually have to, I mean, short term the kind of proof of concept MVP which completely works. I mean, the crazy thing is nowadays you can do, the, so the demo I wrote is using, Web NFC, on the, so which works with Android out of the box. I mean, you can use any Android, GrapheneOS, what have you, Android-based device to, to do it. you can go, you can turn"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:09:54",
      "start": 4194.45,
      "text": "Online for it, but you can write, essentially the split to three cards and then use the cards, to restore them. Where it gets interesting and kind of the direction that I see this going is actually to, so for example, I can say that at Key Labs or the wallets that we've been auditing at Key Labs, all the wallets that we're currently auditing have NFC, integration. So the wallets that will be coming out in twenty twenty-four, twenty twenty-five, they're all gonna have NFC integration, so they could directly interface to these cards. So now Essentially a paper backup, you could have a backup to an NFC card, something in a machine-readable format where it's easy to backup and restore and do all that kind of stuff. and then, it's also interesting because since it's a Shamir split, you could actually, do this in a non-- you could store this with a third party that you don't have to trust in a non-custodial way. So, I mean, I could send it to Stefan, I could put it on a letter,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:10:50",
      "start": 4250.15,
      "text": "you know, on a-- take an Use it for safekeeping, or I could go to essentially have a, a website or some sort of backup service, and they could store, the seed for me, and they wouldn't be able to do anything with it, they wouldn't be able to identify it, they wouldn't be able to identify what, what is this part of, and you could build, essentially, I mean, you could build a, a backup, service around it. So That's one of the things that we're slowly working on, and we're trying to get, I mean, different, for different parts of it, different aspects of it, we're doing, some grants and, potentially some, some equity, financing. So yeah, we'll hopefully have the one implication I"
    },
    {
      "speaker": "stephan",
      "time": "01:11:28",
      "start": 4288.83,
      "text": "can think of is it might change the paradigm instead of, you know, right now the typical, you know, what I'm holding up to the screen here just for the audio listeners is like the typical, you know, writing down your twelve or"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:11:44",
      "start": 4304.92,
      "text": "Listeners, yeah, Stephan didn't just hold up a false, a real, yeah, seed words card, right? But the, but it"
    },
    {
      "speaker": "stephan",
      "time": "01:11:50",
      "start": 4310.14,
      "text": "might change the paradigm where maybe for some users, the, it, you know, instead of having to write down twelve or twenty-four words, maybe it's just like, buy these cheap NFC tap cards and have three splits and write three splits to them and keep those three split NFC cards in different locations, and you don't have to write it down. So maybe it's like a very slick experience."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:12:13",
      "start": 4333.62,
      "text": "Yeah, exactly. So I- I mean, the kind of the, the use case that I have in mind, I mean, specifically where I think it's super interesting is if you think about, I mean, I, I know I'm gonna be, you know, that guy saying about, you know, the under, under the, the parts of the world, that can't afford a hardware wallet, but I mean, hardware wallets are kind of expensive, I mean, if we're being honest, I mean, there's a lot of-- there's a lot of, there's billions of people that can't afford,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:12:44",
      "start": 4364.34,
      "text": "The, the kind of the approach of a smartphone app is more interesting, and then what this is doing is, it's essentially giving them a cold storage backup of whatever they have inside their, wallet app on their smartphone. it's giving them a way to store it in a, in an as cold storage, and essentially what you could do is for the wallet apps, and I mean, this is the kind of stuff that we're trying to, get to, to through grants, et cetera, to be able to work on, and kind of help, people integrate into their wallets. I mean, what you could do is you have a wallet app, and so now you actually store one of the Shamir splits, instead of the entire seed phrase. And so every time you wanna use it, you have to tap the card, for it to be able to restore the full seed phrase"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:13:31",
      "start": 4411.53,
      "text": "and Make sure that, you know, the, that memory contents gets nuked, every ten or fifteen minutes, so you have to tap the card at least once every fifteen minutes to be able to restore the full seed phrase for the wallet to operate. And now we're back in the situation where the risk, is actually mitigated pretty well, the likelihood of you essentially being owned is, somebody has to, do it within, a pretty limited, timeframe,"
    },
    {
      "speaker": "stephan",
      "time": "01:13:57",
      "start": 4437.45,
      "text": "time window. Yeah, interesting. Yeah, so I mean, this wouldn't obviously, Secure your life savings, you know, that you would normally do, you know, but this would be maybe for smaller amounts, it would be very practical to do this kind of thing. Well, I mean, I, I don't know, I would"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:14:12",
      "start": 4452.34,
      "text": "argue, I mean, I would secure, I mean, I, I, I do, I do something, I mean, I came up with this idea 'cause, I do something similar as this. I mean, I would secure my, I would totally feel comfortable securing, my life savings on"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:14:30",
      "start": 4470.11,
      "text": "a, on a, on a, Most people that I know that have a hardware wallet have the seed phrase backup in the same drawer as the hardware wallet. I mean, so the, what's the incremental, benefit of, of keeping it secure on the hardware wallet if you have the words right next to them? I mean, I even, when people ask us, this is like another thing that we've done for a couple of clients, how they come to us and they ask how should they store their crypto? I mean, we tell them, you know, if you're gonna use a hardware wallet Keep your seed phrase there. I mean, what's the, what's the difference? I mean, like your, the, the, the hurdle that you're actually introducing is how do you get to the safety deposit box and bypass all the security? How do you turn it into Ocean's Eleven movie basically, phrase the, another way?"
    },
    {
      "speaker": "stephan",
      "time": "01:15:18",
      "start": 4518.74,
      "text": "But even, I mean, even there, like if you're getting really paranoid, like sometimes they drill the safety boxes and, you know, or like the state can say, hey, we wanna access Dmitry's box at the bank or whatever. So, but I Even there, it could make, it could make sense if that's one of your multi-sig keys and you've got different keys and, you know, no, absolutely, no, but I mean,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:15:39",
      "start": 4539.72,
      "text": "I'm also, also if you split, I mean, you could have, you know, in the, in the case that you're trying to avoid some state actor, I mean, maybe you have, one at home, one at, one with, a family member and then one in a different country or something like this, and so now you're, you're and then they"
    },
    {
      "speaker": "stephan",
      "time": "01:16:02",
      "start": 4562.81,
      "text": "put different locations and all these things, yeah. Yeah, but I guess the other big thing for me though is this kind of-- I like the idea, at least when you're talking about larger amounts, I like the idea of not reconstituting the private key all together in one place because now you're vulnerable in that moment, right? Now, yes, you said, \"Okay, I'll have some kind of ten or fifteen minute timer or timeout thing on the app,\" so that way, you know, it's a, it's a limited time thing. but I guess, yeah, if you're just talking about larger amounts or, let's say for a business, right? Like for a business or a large exchange, this kind of thing, like they might be dealing with, you know, mil-hundreds of millions or more at that level, yeah, they probably do need to have like multi-seg and not keep, you know, not reconstitute the seed all in one place, and keep it, you know, in a very segregated"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:16:52",
      "start": 4612.05,
      "text": "way. Yeah, but for, for instance, yeah. J-just to name, Solutions actually, something called Gnosis Safe, that people use. So it's essentially, you know, like for all intents and purposes, it looks like a web app where you connect a wallet and stuff like this. I mean, it supports Ledger and Trezor, and you can use them, and you're basically doing smart contract, multisig for the Ethereum, stuff."
    },
    {
      "speaker": "stephan",
      "time": "01:17:19",
      "start": 4639.0,
      "text": "Right."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:17:19",
      "start": 4639.28,
      "text": "But the point is, the point is, if you're trying to onboard, ten people, I mean, do you really need to purchase ten wallets or can some In the, in the kind of split, all of this is kind of, implemented as smart contracts in ETH. but what if the less important people just have something like this because they can, you know, you can just, go on Amazon, order a bunch of cards, and now these guys have a quote-unquote, cold storage, backup of their signing key, and when you actually need them, you phone them up, say, you know, load this on your phone for ten minutes, and then we'll,"
    },
    {
      "speaker": "stephan",
      "time": "01:17:54",
      "start": 4674.11,
      "text": "sign"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:17:58",
      "start": 4678.41,
      "text": "this and then go back. The description for this is, this is kind of a replacement for, I, I mean, you could argue this is more of a replacement for something like the paper backup or the crypto steel at the end of the day. I mean, at rest, it totally is, just a, a backup of the seed phrase, but, kind of if you, think about how are people gonna, use this, then, it gets, it gets slightly more, interesting in terms of, you know, i-if you actually, so for Phone, you completely erase it, you take last year's iPhone that you've been keeping in the drawer just for this day, you completely erase it, no Apple ID that you're entering on this thing or anything at all, you just restore it from scratch, you know, load it, send one transaction, I think that solves the issue for, for, a lot of people. I mean, especially if you, if before you do that, you have to collect them from, at one location to be able to restore them, I mean, like you said,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:19:00",
      "start": 4740.49,
      "text": "Storing the entire seed phrase, reconstituted, on, on a, on a device, which is the, the kind of the actual issue, going back to the hardware wallet."
    },
    {
      "speaker": "stephan",
      "time": "01:19:09",
      "start": 4749.91,
      "text": "Right. Yeah. Yeah. Interesting. Okay. So, Yeah, what's the-- so I guess you're looking for support with the backup thing, right? So what can-- if people are interested, what's the best way for them to kind of find out more about this or get in touch?"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:19:23",
      "start": 4763.12,
      "text": "Yeah, so we'll have, we'll have links below. So the working name for this is, recovery tag, we're working on this. So we're trying to get some grants,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:19:35",
      "start": 4775.03,
      "text": "so, I mean, to, to work on this, so not, I mean, I'll, w It's been, longer than what some of the other great organizations that, that I've gotten, in touch with on some of the other, blockchains, so I'd be curious, to kind of have this, as well. I mean, just to give you a couple ideas of where, it can go. I mean, in theory, if you don't have to trust the third party, just in theory, I mean, this one, this one isn't, fully fleshed out, but you could even, you know,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:20:13",
      "start": 4813.57,
      "text": "be able to, recover it. So, I mean, there's stuff like that that you could, do, in Bitcoin. I know, I know you just started a gigantic discussion on ordinals on, on this episode, but, stuff like that might, might be better than, than, than these,"
    },
    {
      "speaker": "stephan",
      "time": "01:20:28",
      "start": 4828.07,
      "text": "retards, as I prefer to call them. But, yeah, so, yeah, I mean, yeah, I guess theoretically people could do inscriptions, although- Is that really the best place? I don't know. no, I would, I, I mean, I,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:20:39",
      "start": 4839.45,
      "text": "so I, I think that ultimately, I mean, I think we're gonna eventually have, we're-- I mean, so the goal is to, to kind of fund, a lot of the open source stuff for all this to be open source, for there to be native, Android and iOS apps that are open source, that the people can then essentially take the library, integrate it with them, and eventually we'll and so, I mean, we're probably eventually gonna have our own service that we host that if you wanna kind of support us in our project, you can use that. but the, the, I mean, somebody, I mean, somebody, another non custodial, you know, multisig provider could offer this at, kind of as a lower tier service that doesn't, require as much, white glove treatment or something like that. So, I think there's gonna be a lot of, innovation. I mean, so if we The biggest missing piece where I do see stuff happening is, you know, in multisig and, and kind of how to, how do I actually store my backups? Because, at the end of the day, you don't wanna end up in the situation that you're looking for, crypto recovery service that's gonna take a percentage, fee, to recover, recover your crypto."
    },
    {
      "speaker": "stephan",
      "time": "01:21:57",
      "start": 4917.25,
      "text": "Right, yeah, and, you know, it could make sense, you know, in different contexts where maybe it's not the backup for all of your seeds, like maybe it's like the backup for one of your, out of your multisig keys, and, you know, this is kind of the one that's split amongst your lawyer and your accountant and someone in your family or whatever, and it's like a recovery sort of, in the case that, you know, you die or get disabled or something, like it's- Yeah,"
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:22:23",
      "start": 4943.85,
      "text": "exactly. I mean, I, again I mean, you know, ranging from, you know, somebody was in an accident and forgot, their, you know, whatever passphrase, seed phrase, PIN, to, you know, someone passed away and now it's on a ledger blue, and now they can't get to it. I mean, a lot of the stories are depressing. I mean, people, people should put more thought on, you know, how to pass their crypto along to their loved ones after they pass away, I mean, sooner rather than later."
    },
    {
      "speaker": "stephan",
      "time": "01:22:52",
      "start": 4972.48,
      "text": "Alright, well, I think that's, pretty good, spot to finish here. yeah, at the end of the day, there's, there's a lot of different stuff we went through today, so, around, you know, hardware security and, practical, you know, what does it mean, tips. so yeah, Dmitry, thanks for joining us and sharing your insights about, hardware security."
    },
    {
      "speaker": "dmitry_nedospasov",
      "time": "01:23:13",
      "start": 4993.59,
      "text": "Yeah, thanks for having me, Stefan."
    },
    {
      "speaker": "stephan",
      "time": "01:23:15",
      "start": 4995.83,
      "text": "Alright, I hope you enjoyed the show with Dmitry and maybe you learned something about Bitcoin hardware security and where things are at and where things are potentially going in the future. I hope you enjoyed the show. Make sure to press like and share it out there with family and friends. That's it for me. I'll see you in the citadels."
    }
  ]
}
