{
  "episodeId": "SLP599",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "stephan_livera": {
      "name": "Stephan Livera",
      "role": "guest",
      "tag": "STEPHAN"
    },
    "guest_2": {
      "name": "Guest 2",
      "role": "guest",
      "tag": "GUEST"
    },
    "guest_3": {
      "name": "Guest 3",
      "role": "guest",
      "tag": "GUEST"
    },
    "guest_4": {
      "name": "Guest 4",
      "role": "guest",
      "tag": "GUEST"
    },
    "guest_5": {
      "name": "Guest 5",
      "role": "guest",
      "tag": "GUEST"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:11",
      "start": 11.11,
      "text": "Hi everyone, and welcome back to Stephan Livera podcast. Today we're doing something a little bit different. We're doing a bit of a hardware and Bitcoin security panel. we'll, we'll chat a little bit about Dark Skippy and other related ideas. So joining me, well, I think pretty much everyone here is rejoining, is a, a returning guest. So we've got Salvatore from- Ledger, we have NVK from CoinKite, we have Craig Raw, known for his work on Sparrow Wallet, we have Reardon Code, aka Brandon Black, working on, Swan Vault, but with, experience at BitGo and Casa, and we also have ADDBTC, joining us to share some expertise on hardware. So, welcome back to the show, everybody. Hey, glad to be here. Nice,"
    },
    {
      "speaker": "stephan_livera",
      "time": "00:52",
      "start": 51.91,
      "text": "nice to be"
    },
    {
      "speaker": "stephan",
      "time": "00:52",
      "start": 52.35,
      "text": "back. Great. Great. Well, so look, let's start with, obviously Dark Skippy, I think"
    },
    {
      "speaker": "stephan",
      "time": "01:00",
      "start": 60.0,
      "text": "Might be interesting for people, you know, if you wanna sh-share some initial reactions and, we can get the conversation started that way."
    },
    {
      "speaker": "stephan_livera",
      "time": "01:12",
      "start": 71.67,
      "text": "this isn't a new thing, like, you know, nonce attacks are, are like quite a few years old. you know, the, the folks, from, I think, Blockstream and BitBox worked on anti-claptrap protocol, many years ago now. and, you know, there is an adequate solution, in my opinion, which is the RFC 6979, which is deterministic nonces plus, you know, deterministic- builds and secure boot, you know, those three things together, are sort of like the alternative to, anti-clapto protocols. and, you know, I'm not sure if you want to get into the weeds of that specific attack for, for this show, but it, it's not something new. I think it's an important sort of thing to mention, and, you know, it is something that concerns everybody here who works on this, on Bitcoin security, but, but it is fairly like mitigated It, do, do we want like a good solution, to, to this attack? Absolutely, I, I think everybody wants. but, you know, nothing is without trade-offs, and the current trade-offs for you to have that is, use of USB, which, you know, some of us are completely like against USB use, prefer air-gapped solutions, some don't. there's varying opinions on this. But, but essentially, like in a nutshell, that's sort of like where we're at in the, in the industry with this. I, I, I don't think there is anybody here who's freaking out about this attack, including the, the, the people who wrote the paper."
    },
    {
      "speaker": "stephan",
      "time": "02:52",
      "start": 172.44,
      "text": "Right."
    },
    {
      "speaker": "guest_2",
      "time": "02:54",
      "start": 173.95,
      "text": "Anyone else wanna jump in here? Yeah, I would, I would love to jump in and just say that it's really, really important when we're talking about any kind of attack or threat, whether it's in general software or in self custody software, to think about the threat model and, and the threat actor who's going to actually take action on this attack and how they're gonna target people and how they're gonna get this attack actually to the end user victim. And I think that's what's kind of lost is like, this attack looks so bad, if this software gets on a Exfiltrate the nonce in just two signatures. Okay, but how did it get there? What was the path? Who was the threat actor who got the software there? Who modified the hardware in transit? How did they intercept the hardware without anyone knowing? Like all of these other things are part of the threat model, and so we have to keep in context the entire threat model, not just, \"Oh, this looks so bad in this very isolated case.\""
    },
    {
      "speaker": "stephan_livera",
      "time": "03:46",
      "start": 225.69,
      "text": "Yeah."
    },
    {
      "speaker": "guest_3",
      "time": "03:49",
      "start": 229.11,
      "text": "Yep. So, I'll jump in as well. so first of all, shout out to Robin and the others for, for the paper was, for the paper or for the website, was really well written and well, well presented and it's, definitely improvement over the previous ways of doing this kind of attack. I think the main- The biggest difference, apart from being more effi- more efficient, is the fact that, it no longer requires the, the device itself to do expensive grinding that would have been, harder to hide on, on embedded devices that are quite weak in terms of computational power because, because it moves The grinding more on the receiver of the communication rather than the sender. I, I think that's the biggest practical difference between, how the attack will be done before with nonce grinding compared to how it's done in, in Dark Sky. but, but yeah, I agree with Rearden that, you, you need to put the attack in the category of all the possible things that in that security model, you can do. So what are all the possible malicious behavior, behaviors a hardware wallet, that is compromised could have? And so mitigating one specifically, only makes sense if one looks at the whole class of other possible misbehaviors and is that the most practical way of of putting a backdoor in a hardware wallet, I think there are other ways that are, almost equally bad and, so it only makes sense to mitigate if you can protect yourself from, from many of, or all, or possibly all of them at the same time."
    },
    {
      "speaker": "stephan",
      "time": "05:21",
      "start": 321.29,
      "text": "Craig, I think you just to get your, go, go on, Andrew. Go ahead, Craig. Yeah."
    },
    {
      "speaker": "guest_4",
      "time": "05:25",
      "start": 325.11,
      "text": "Yeah, sure. y- my thoughts on it are, well, you know, firstly, I, I think, you know, it's well worth listening to the podcast you did, to, to Stefan about two episodes ago. and I think it was a very reasonable takes there. in terms of, there's no need to panic, there's no need to change anything now. I think it's, it's an interesting new attack I mean, there are many different kinds of attacks and mostly they are not the way you are likely to use your, lose your, your funds. There are much easier ways to lose your funds. So, if we can find a way to, you know, make signers, less risky to use, to kind of take away these edge cases which are very unlikely to happen, but nevertheless could happen, without any real cost, then great, we should do it. what we should try and avoid Avoid though, because, you know, the other part that's not really talked about is the user experience. It's not just security, it's not just privacy, but it's also the UX, the kind of, what is the experience like? And if you are, for example, having to do multiple rounds of QR scanning, for an air gap device, that's likely gonna be, really not a nice, a pleasant user experience. And, you know, those are the kind of things where, you know, you don't see people Talking about that quite as much. so, it sounds very much like the authors of Dogecrypto are aware of that and they are, you know, working on a solution which doesn't involve, involve that. We'll have to see if there are any other downsides like, bloating the PSBT size or anything. but, you know, I'm, I'm sort of a believer in making practical products that people want to use, not trying to make the most secure product that no one uses because it's simply too hard to use. so there is a That's kind of, how, I see it and I hope that we have a practical, you know, improvement in future, but I'm not particularly worried about this attack today. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "07:32",
      "start": 451.9,
      "text": "Okay, ADD BTC, we haven't heard from you, so, if you have any comments or responses to the other panelists."
    },
    {
      "speaker": "guest_5",
      "time": "07:38",
      "start": 458.14,
      "text": "Yeah, I'll piggyback off what Craig said. So for, for everyone that doesn't know me, I've, I've got a experience in consumer electronics for almost twenty years now. I've shipped millions of products. so, so my experience isn't in the Bitcoin world, hardware-wise, but it's outside of that. So consumer electronics, making devices for people that, need to be secure, need to be usable. And And, like Craig is saying, there, there is a perspective where how far is too far for not even just the average user, but for normal users to get, in a place where they just pawn themselves. and, and that's something I've been really critical and gained some attention on, on Twitter for my calling out of SeedSigner and, the lack of signed updates o-ultimately is one of the most problematic parts of that hardware. and, and this, this issue, along with many others, can be mitigated by that one- One, that one factor, a simple signed hardware where you have an internal signing that checks and makes sure that the vendor that, vendor's software, the vendor's signature is checked and approved before purs- pursuing boot on the device. And it's a simple thing, and, and specifically, one of the reasons that this was used on SeedSigner was that it, it was not present and, and easily easily loaded software ran with, with, with no knowledge of, what the original code was intended to be, and, and, and this is a real concern. I-- this is a concern in consumer electronics in general, in most companies that are legitimate, that are producing stuff, especially here in North America and Europe. are coming to the same conclusion that, that most devices need to have some sort of, internal, confirmed signature of the vendor. and, and ultimately, that's what happens is the, the trust needs to rely somewhere ultimately, to some point where you, the user, and the vendor can have an agreement ahead of time that you can say, okay I, I can't trust anything, but I can at least verify that this vendor, signature is correct and, and there is a level of trust there that it's hard to avoid. I mean, o-ultimately, I think the, the best way to avoid this would be you calculating your, your, or doing all the calculations and the encryption yourself on a pad of paper, maybe with a, with a very simple calculator that, that doesn't do anything, right? And, and mathematically that's difficult, and practically it's impossible. So, and my, my perspective is coming from the point of how, how little hardware do you need and how little user interface do you need that's practical and secure. So."
    },
    {
      "speaker": "stephan",
      "time": "10:20",
      "start": 619.94,
      "text": "Yeah."
    },
    {
      "speaker": "guest_5",
      "time": "10:20",
      "start": 620.44,
      "text": "There's a"
    },
    {
      "speaker": "guest_2",
      "time": "10:21",
      "start": 620.62,
      "text": "calculator vendor in the chat."
    },
    {
      "speaker": "stephan",
      "time": "10:23",
      "start": 623.05,
      "text": "What's"
    },
    {
      "speaker": "stephan_livera",
      "time": "10:23",
      "start": 623.19,
      "text": "that?"
    },
    {
      "speaker": "stephan",
      "time": "10:24",
      "start": 624.25,
      "text": "There's a calculator vendor in the chat. that's right, that's right. Right. Yeah. You"
    },
    {
      "speaker": "stephan_livera",
      "time": "10:28",
      "start": 627.81,
      "text": "know, it, it's funny because, you know, it's known, right, for, you know, the decades now that, you know, the, the best, like, reasonable practice Practical way of handling a lot of this is by, you know, software attestation, right? Like so, in secure boot, so the, the device does its best to remain whole, right, so that it can attest that the firmwares coming in is good by the manufacturer, right? Like, is that perfect? Absolutely not, but, you know, it does create like a few orders of magnitude more protection, right? Because you're, you're not just getting something that, that you can't like probe in all parts of the system in order to find out if If it's doing what it's supposed to do, right? you know, the, the guys from Ledger, Salvatore's here, like they, they have a different model, right, where you're trusting the vendor, you know, these guys are huge and, you know, they're gonna get sued to death if they do something stupid. And, you know, there is trust, right, at some point in the, the stack if you can't verify everything yourself, right? I think we're at a place that's insanely amazing already. Like, you know, with, with Hardware, I mean, like you can, you can verify every line of code, you can buy the chips yourself from DJ Key, l-like replace them on the hardware, load the new firmware in, and, and validate that's doing what it's supposed to do. Like, it's, it's pretty crazy and it wasn't possible before the, the Bitcoin space was around. And, you know, I think this, this whole conversation got a little bit like muddled because there is like some hardware out there that essentially has no physical security to it, and, and it was used as the means to display this attack. and, you know, it, it created some confusion in the space as to like what's possible and what's not possible, right? and, and just sort of like a, it's a quick side note here, it's like, you know, if you don't trust the manufacturer and you can't check it, I mean, a manufacturer Right? Like, I mean, they can just ship, you know, a rainbow table of private keys, you know, in the device. They don't have to get creative with like nonsense, right? There is many other ways of doing this. So, a-and some of the hardware that, that does have a Taproot protection, like, doesn't have other kinds of protections, right? It, it does different kinds of trade-offs. so, you know, this conversation is, is extremely complicated when you get into the weeds, because it's like, what group of trade-offs you For maximum sort of security versus practicality, right? And, and I, and I think like the space itself is very good. We haven't seen, you know, at least with the major manufacturers, like we haven't seen any sort of like attacks that like take the Bitcoin from people out of these devices. So, you know, again, it's, I, I feel like some of the reaction i-is a little bit misplaced, i-is like maybe because it's like people that don't work on hardware, have sort of like a lot of opinions about it, but I think we're in a pretty good place. Okay,"
    },
    {
      "speaker": "stephan",
      "time": "13:29",
      "start": 809.13,
      "text": "yeah. and so I guess as I'm understanding it, what we're talking about here is this idea that, you know, it shouldn't-- we shouldn't be sort of absolutist about one particular attack, just because there's one particular attack that's out, it doesn't mean that everything has to be put against mitigating that one way of getting pwned, right? There are multiple ways to get pwned, as he said, and as you mentioned, as AED has spoken about, as NVK has spoken about with secure boot, it's this"
    },
    {
      "speaker": "stephan",
      "time": "13:59",
      "start": 838.81,
      "text": "is shipped with a way of checking the, the firmware updates that are being sent to make sure that it's correctly signed by the manufacturer. And so the point of that means it's a lot harder to be pwned in terms of using, incorrect hardware, though obviously not impossible. you could have been sent a, a wrong device from the start, and I guess at that point, you know, you were just pwned from the beginning. so I guess that's one way to put it. maybe- Maybe it's important to, let's put it in context then. So, you know, speaking today, August twenty twenty-four, what are some of the ways that users lose coins? I guess historically people, it was user error, it was people losing their backups, or maybe device failure. Like, what would you say if you guys had to just kind of comment, what were, what were some of the ways people lost most of their coins? And, you know, do you see that as, you know, how, how has that changed over time, right? Maybe in the early days, certain attacks And now it's gonna be this, and in the future it'll be something else."
    },
    {
      "speaker": "guest_2",
      "time": "15:03",
      "start": 902.63,
      "text": "I think bad backups were historically like the most common way to lose coins. People just didn't have their seed backed up at all, or before seed, it was just a bunch of private keys, and people lost coins that way. I think I lost some that way. and then subsequently, I think it's really been mostly the social attacks. You know, that's, and that's part of why hardware devices are so important, because they help protect you against certain categories of phishing attacks. so"
    },
    {
      "speaker": "guest_2",
      "time": "15:29",
      "start": 928.53,
      "text": "Scammer that called Junseith, like that subcategory of attacks is now the most common way, and then along with the, the ones that Lock reports, the physical attacks. Y-you know,"
    },
    {
      "speaker": "stephan_livera",
      "time": "15:38",
      "start": 938.18,
      "text": "if I have to like attribute, like I, you know, don't have hard data for this, it's impossible because most people don't even talk about it. We, we hear privately as, as vendors a lot of horror stories. so I, I'd say number one is exchanges. I mean, through time, I still remember the very early days. I mean, I was at mywallet I can't remember now. there's been through time, it's like leaving your money in the exchanges is probably like the number one way of losing your money. a-and that sort of spills over to the social attacks, because then people convince you to give your password to the exchanger or reset your password, and then they get in. a- another one that was quite successful actually is, you know, people get DM'd and say, \"Hey, I am from this major manufacturer. can you please give me your seeds so I can help you,"
    },
    {
      "speaker": "stephan_livera",
      "time": "16:30",
      "start": 990.13,
      "text": "People fall for that because they don't understand what a seed is. you know, people with paper backups, especially pre-BIP eighty-nine, s-s-sorry, thirty-nine, right? Like people used to have in BIP thirty-two, people w-would have one private key per, per UTXO, so, you know, people would, would lose. I mean, like, God knows how much Bitcoin I have lost in, in, paper backups that, you know, went to the washing machine. And, you know, like computer, like people have like private keys on their computers, especially Windows, and, you know, even Bitcoin Core, Bitcoin Core way back in the day had, you, you know, a major hole because people didn't set up a password on their RPC, so their coins got taken. you know, computers are One major hole, right, especially Windows, people get take, get their coins taken away from them that way if they aren't sitting on their computer, their phones, people get mugged. It, it all, it's, it's, it's tricky, but, you know, from people having hardware wallets and using hardware wallets, it, it, you know, it's very rare that you hear a story of somebody that, you know, maybe was not forced, with against their head to, to give up their coins."
    },
    {
      "speaker": "guest_4",
      "time": "17:42",
      "start": 1061.93,
      "text": "Yeah, there's, there's, I completely agree with what's been said. down on the kind of, this happens like a thousandth of the time of any other kind of attack, that entropy is the kind of"
    },
    {
      "speaker": "guest_4",
      "time": "17:56",
      "start": 1076.16,
      "text": "You do see it from time to time, someone will use a device which had bad entropy. We had the case of that library recently, which was creating seeds with bad, bad entropy. And in fact, the cold card as well allowed you to create a wallet, without a minimum number of dice rolls, which has now been changed. But, a few people, I wouldn't say many, but a few people kind of went out there and rolled their dice ten, ten times, and that's just- Just not enough, so they lost their funds. it's a great, bold story, bold, bold accident story. Yeah. So, you know, bad entropy is, is-- and I think this was actually also mentioned, by the Doc, the Skippy guys, you know, 'cause that's ultimately the source of most of these kind of attacks, that happen on the signer, so that's, that's definitely one, if you are wanna be super secure, definitely wanna add your own entropy to the entropy that the device provides. provides. so that's one that I would add in that I've seen from time to time."
    },
    {
      "speaker": "guest_2",
      "time": "19:01",
      "start": 1141.37,
      "text": "Just to, to be clear though, the bad entropy attacks on hardware wallets have been when someone tried to do their own entropy and failed, not on bad entropy actually from the device. So I, I mean, I, I agree that adding entropy is good, but be very mindful of how you're doing it."
    },
    {
      "speaker": "stephan_livera",
      "time": "19:14",
      "start": 1154.32,
      "text": "You know, it's, it's hard to take, it take the, some of the stories at face value and, you know, somebody rolls ten, ten dice rolls or, you ninety nine times, y-y-you know, like, I, I mean, i-if a hardware wallet was able to know the exact entropy amount that you entered, y-y-you know, you would be As capable as breaking that entropy, right? So, y-y-you know, we try to do our best, you know, try to protect against some stuff, but, you know, there, there really is a limit, right? Because that's the inverse problem."
    },
    {
      "speaker": "guest_4",
      "time": "19:50",
      "start": 1189.59,
      "text": "Yeah, I mean, I actually have, have an open issue, on Sparrow where people want me to implement user-created entropy, and I, I'm just, I think the downsides are greater than the upsides. I think people are more likely to lose funds from doing that than improve Prove things, so I currently have no intention to implement that. But it's just an ex-example, you know, the reality is humans are extremely bad at being random."
    },
    {
      "speaker": "stephan_livera",
      "time": "20:18",
      "start": 1217.86,
      "text": "I, I think, I think what's cool about the dice, and it's good that you brought that up, is that, you know, it's a way to prove that the vendor is honest. It's not a good way for you to do it in entropy. You, you know, it's just one more item. Like, but, you know, one thing I do love is like the mix of user-generated entropy plus the device doing hard math, right? And, and breaking that up into good entropy with its own random number generator, right? So combined entropy is a fantastic way, You to have like some certainty that device, you know, like we don't even have to talk about being malicious, right? There's just bugs, bugs happen, right? So, you know, with this added entropy of the user on top of like some very high quality TRNG and, and also some Schnorring, Schnorrings of, of, other parts of the device, like, you know, you have like some, some reasonable guarantees, right? That, that things aren't being messed with even by bugs. I, I really like that sort of For, for this kind of stuff."
    },
    {
      "speaker": "guest_2",
      "time": "21:19",
      "start": 1279.29,
      "text": "And, and we should like kind of look at other industries, that, that's how, all of the kind of Linux and Unix kernel managers for entropy have gone over the years. They, they have gradually found more and more little sources of entropy and they XOR them all in, so the end result is good entropy, even though most of those sources might be crap, because they've mixed everything together. And so we should take the, the knowledge from the other industries and use it for ourselves."
    },
    {
      "speaker": "stephan_livera",
      "time": "21:45",
      "start": 1305.12,
      "text": "I mean, one of the, one of the The running theories for Luke's, loss of, two hundred BTC, based on his PGP keys, that like he used at specific systems, there, there was a vintage of, of some Linux that he used that had a massive hole, or was the hardware, I can't remember now, or was the hardware in the computer that had a massive hole on its entropy creation, right? And then boom, money gone. You know, it's, y- there, there is professionals on the market now offering devices that are like really good, and, and the people who can read the code like agree that they think it's really good. A-and there, there is like a lot of them that are actually really good, and, and people can choose which one, y-y-you know, most fit their, their, their, their sort of preferences, their, culture, their whatever, right? So, you know, if you're using a commercial- World device in the market now, you're doing very well, right? And, and if you don't like them, just use three of different ones in multisig, and, you know, all this, this conversation is completely out the window, right?"
    },
    {
      "speaker": "stephan",
      "time": "22:54",
      "start": 1373.88,
      "text": "Yeah. One other question around entropy while we're here, this is something I recall from my earlier podcast, the Dark Skippy one, talking with Lloyd and Nick and with Robin. One point I think Lloyd was making was kind of distinguishing between entropy at the point of key generation, right? So people might do, you know, dice rolls or something like that and generate, and that's part of how they're generating their twenty-four words, which then, you know, that creates, that's the master private key, then the master xPub, and you're having addresses off of that. But he Making sure we've got enough entropy at the time of signing, when you're signing a transaction, right, when you're going to send some Bitcoin. I'm curious if anyone on the panel here has thoughts on that. Is there something more that has to be done there, or is there something different that could be done at the time of signing for entropy?"
    },
    {
      "speaker": "guest_2",
      "time": "23:41",
      "start": 1421.4,
      "text": "I mean, for single sig, okay,"
    },
    {
      "speaker": "guest_4",
      "time": "23:44",
      "start": 1423.54,
      "text": "yeah, you, you actually don't use entropy if you're using the RFC sixty-nine, seventy-nine, because we're all creating, I mean, everyone using that approach is doing it and doing it in this very specific way that Bitcoin Core does it, so we all create byte for byte the exact same binary signatures, and we can compare those byte, byte for byte. Now, if we were introducing our own randomness into the process, then obviously that wouldn't be byte for byte the same. So, it's, it's only in the case that You're not following that exact process that you would be trying to introduce your own entropy. So,"
    },
    {
      "speaker": "stephan_livera",
      "time": "24:17",
      "start": 1457.18,
      "text": "and, and I think this is an important point to bring up because, you know, when you ask a cryptographer what's the solution for something, it's more cryptography, right? so, the, the boys from, from FrostSnap are, are like, they're hard, like, thinking about, like, doing, Schnorr, right? And, and doing, Frost. So, and, and for Frost, like, you need the nonce to be Extremely. It's a problem they already have"
    },
    {
      "speaker": "stephan",
      "time": "24:43",
      "start": 1483.0,
      "text": "to deal with, yeah."
    },
    {
      "speaker": "stephan_livera",
      "time": "24:44",
      "start": 1483.92,
      "text": "It's a problem they have to, and, and there is no good solution yet on how to do that, right? So they're, they're, they're still working on how to defrost, because you have to essentially pre-share nounce, right, to, to use. so I think their headspace is like on that, and that's probably why they arrived at this. so they were trying to massive nounce, to properly defend them later for frost, and, and I think it But, you know, when, when it comes to this, I, I, I think it's probably the reason why Core doesn't have an alternative to sixty-nine, seventy-nine, right? Like, the, the, the Core uses this deterministic nonce as well, and like, there hasn't, like, I, I mean, like, Anticlaptop isn't even a Bibb. Like, you know, like there, there is no accepted sort of market solution for this. There's only two vendors that are of smaller install bases that use this solution, right? Like, like the majority of the market isn't there. mostly, I believe, because of, you know, the trade-off of the USB and also the, the UX issue with this protocol, which is very good, but, you know, it requires multiple rounds, right? So, I, I think we're just not quite there. on the good side though is this, this whole drama sort of sparked a lot of good conversation and, and there is work being done now. So, Moon Sutler just proposed something. we have some code being r-written internally now that we hopefully will talk to him soon. It actually happened this morning. you know, maybe, maybe we come up with a solution that is acceptable, but I have a feeling that because this touches cryptography, there's gonna be a lot of opinions and, and sort of backsheds And so there may be a few different standards on how to deal with this, but, but I, I, I think solving this problem is a good thing because it, it, it de-risks the vendor even one more step. but, but, you know, again, it's-- I, I don't, I don't think it's a, it's a concern"
    },
    {
      "speaker": "guest_2",
      "time": "26:46",
      "start": 1606.33,
      "text": "Yeah, and I wanna throw in there, it, it, we use RFC 6979 for ECDSA, but there's no equivalent standard actually for Schnorr signatures. So if you're using Taproot single sig, the core, or the, sorry, the BIP recommended way to do it is with auxiliary randomness, but it has this very like nuanced take where it's like, if you have a good source of randomness, use it here. but of course, not every hardware device does at all times. So there's, there's these nuances in all of these things."
    },
    {
      "speaker": "guest_2",
      "time": "27:15",
      "start": 1635.0,
      "text": "with these multi-party signing protocols, whether it's Froste or MuSig 2, this is even more nuanced. that's why when I was working at Bitcoin, I worked with Jonas on the MuSig 2 bit, having the, the ability for one signer in MuSig 2 to be deterministic and still use deterministic nonces Because it's hard to guarantee ongoing good entropy, especially on embedded devices. So perhaps it's better to have some way to do deterministic signing for one of the signers that might be a hardware device in a multi-sig or frost quorum. So there's a ton of nuances in all of this stuff, and we do need to be careful of saying always use deterministic nonsense. Well, you can't do that for every protocol. Always use random nonsense. Well, there's not always good randomness. There isn't an always, and device manufacturers and researchers kind of- Do a lot of work to make the right trade-offs for their devices."
    },
    {
      "speaker": "stephan",
      "time": "28:06",
      "start": 1685.82,
      "text": "This show brought to you by mempool dot space, the world's leading Bitcoin visualizer, and now they've got an accelerator program. So if you have a transaction that you sent at a fee that was too low to get confirmed, now you can fix this at, with the mempool accelerator. The way it works, you can go and search your transaction, scroll down, click accelerator, and you don't need an account, you can pay with Lightning, and then it'll show you it's now in the process of being accelerated, In minutes, it's confirmed. And so this is a great way to help you out if you are stuck, and this can happen where maybe your wallet doesn't have RBF or CPFP, or it might help you in situations where it's impractical to go and re-sign. So for example, multi-sig with keys in different locations. And thirdly, even in some lightning scenarios, perhaps a forced close, you might not be able to use RBF. And so in this case, the mempool accelerator can help you out. So keep it in mind, and you can find out more over at And now back to the show. Back to the show in a moment. This show brought to you by CoinKite dot com, the creators of the best Bitcoin hardware security devices, such as the Coldcard Mark IV and the new Coldcard Q. Now, we use Bitcoin hardware security devices to keep our keys offline, our private keys offline. Now, the way these work is you can do that setup, write down your twelve or twenty-four words on those, the seed word cards, and keep that secure. Now, you can use this device to in- Interact with the Bitcoin network using software such as Sparrow Wallet, Electrum, or Bepco Desktop or Nunchuk as a few examples. Now, you have a range of security features that you can use with these devices such as passphrases. You can use seed x or, or my favorite is multi-signature. Now, if you're starting in a basic way, just start with the device and the USB-C cable, plug it directly to the computer and use it that way, and then later improve your setup. But I believe these devices are great at helping Being secure your coins, especially as you start to migrate up into multi-signature security. But don't be disheartened or don't be, scared away. They are accessible, and I think you actually do learn about Bitcoin in the process. So to get yours, go to coinkite dot com, use code livera to get a discount on your cold card. And now back to the show. Yeah, so it sounds like really it's very case by case, and so perhaps some of the nuance gets lost in kind of online, shorter form discussion, because then people are sort of Saying, \"Oh, see, if you're not doing this, that, and that, like, that's not good,\" or, \"And then it's sort of like maybe it makes sense in this context, but not in that context.\" so, okay. the other element of this is that currently only, well, two devices have Anti-XPub, and obviously the big part of that is it's USB. Those devices are USB. Oh, I, I mean, to be fair, Blockstream Jade has QR, but doesn't have Anti-XPub, if you use that,"
    },
    {
      "speaker": "stephan",
      "time": "31:00",
      "start": 1860.16,
      "text": "Curious, I know NVK, you're obviously quite, strongly against USB, how much-- can you, I guess, put it, put, put it into context for us. What are the main risks of USB connection and put that into context for us? And then if anyone else has a di-different view, let's hear that."
    },
    {
      "speaker": "stephan_livera",
      "time": "31:18",
      "start": 1877.51,
      "text": "I, I think, Ed BTC is gonna have an interesting take on this as well, as, as he, so, wisely, tweeted this, the universal serial bus. It, it, it is an absolute clusterfuck. I highly recommend people go read the, the USB spec. i's, i's a ginormous, like, ginormous, like, problematic thing. i-it's, it's unsafe, in my opinion, with most of the sort of like, ARM platforms or any, any sort of like device that, that has a more general purpose chipset. you know, for computers, I'm not even-- it's insane, right? Like it's Horrible. you know, Trezor had, USB attack way back in the day by power differential analysis, right? So they were leaking private key through the USB power bus. the, I, I, Salvatore, you might be able to correct me, but like there was some USB sort of like attack on, on original ledgers way back then, that, you know, it was sort of researcher, it wasn't seen in the wild, you know? Trying to secure USB is very difficult. another aspect that people that don't do hardware often sort of miss is that the same way you program a lot of these hardware wallets at the factory is through the USB, serial. so a lot of them use UART. and, you know, so for example, say like BitBox, right? Like the, the same ports you're using to program the device and change firmware on the device, you're using Later on by like, say, like making it more hardened, you know, cold card allows USB, is extremely strong protection on the USB, you know, but understanding The understanding I have on USB precludes me from suggesting people should use USB unless it's for small amounts of money or, for multisig. Then, you have specialized hardware, right? So for example, the, the folks from Ledger, what they do is they have a smart card chip in there that is designed to be extremely restrictive, right? So, so they can achieve a much higher level of security on the USB, and, and I think one of the reasons why they feel comfortable using it. but, but then you have other trade-offs, right? Now you Java platform, it's closed source, in terms of like being not being able to, to review the code, like none of these things are without trade-offs, and, and in my opinion personally, I don't trust USB, especially on things like a Raspberry Pi or, or like even more complex devices like that. I, I don't think it can be secure to an adequate, level, especially not because people are malicious, just because bugs happen, right? and, and, you know, if you can, if you can close something down, it means it was open to begin with. and, and it's not a good, methodology for when you're trying to secure, Bitcoin in the way that it's, the, the way that works. so, so that's sort of like my view on this."
    },
    {
      "speaker": "guest_2",
      "time": "34:28",
      "start": 2067.8,
      "text": "I wanna throw one really quick thing in that I really wanna hear from AddBTC as well. But if you're, if you are assuming malicious hardware, which is kind of the context we're in in talking about Dark Skippy, if you assume malicious hardware and you're gonna plug that into a computer, the malicious hardware has already won. As soon as you plug a malicious USB device into your computer, it has won the war. You don't have to plug"
    },
    {
      "speaker": "stephan_livera",
      "time": "34:51",
      "start": 2090.68,
      "text": "in. Some of them would just beam out, you know, like you do, like there is many attacks that you can, you know, say the HDMI port, or you can actually do LoRa from a Raspberry Pi, without an antenna. So the, the point is like, you know, a malicious device just gives you bad entropy. Like, I, I mean, there really is nothing better than that,"
    },
    {
      "speaker": "guest_2",
      "time": "35:14",
      "start": 2113.74,
      "text": "assuming, let's say, you, you, you make your own seed using, entropy from SeedSour or my dice rolling thing that I've published, like, there's ways you can get a good seed into a malicious device, but then as soon as you connect that to USB, that device Guaranteed can exfiltrate that seed, whether you sign a transaction or not. The malicious hardware can exfiltrate the seed if you plug it in, period."
    },
    {
      "speaker": "guest_5",
      "time": "35:36",
      "start": 2135.54,
      "text": "Yeah, and, and I think my concerns with USB are, you're, you're plugging this thing that's so simple into a, Something that has unlimited resources, relatively, right? So you, you have this computer that has RAM and internet connection, who knows what you're plugging it into. The, the abilities of what it can do to, to USB is, is enormous. Now Yeah, like, like if you have, if you have a very simple device that it's plugging into, not a full-blown USB five physical interface, there, there's more limitations on what can happen there. but, but somebody had, had recently mentioned, just put this FTDI, UART to USB converter between, between your processor and, and the USB. and if, for those of, for those of you that don't know, this FT device, FTDI device is, is used everywhere, and it's probably, probably one of the most counterfeited products Ever, ever to be counterfeited, because it, it's such a simple function. It, it takes, it takes USB, it creates this USB interface, and it converts UART to, to make a virtual COM port for your, for your laptop or your, you know, your desktop, whatever you're trying to connect it to. So, so in Asia, they produced these things and, and duplicated these things, and they're, they're everywhere. And about ten years ago, e-everyone knew that they had a bad device because there was some Windows driver that FTDI, pushed. I don't know if you guys remember this, and, and everyone's parts started to stop working, and they were like, \"Well, what is this? What's going on?\" And the FTDI company decided to push this, this driver that locked out all these, all these counterfeit FTDI, But, but the FTDI device itself now becomes your target, and this thing isn't made for security, obviously, it, it could be counterfeited, but, all it takes is a vendor ID change, a, a configuration change of the part, if, if it's done externally or at the factory or whatever, and now you have a, a virtual keyboard, a mouse, a, a, a modem, I mean, everything that USB can be, that device can be. So, so sure, you're, you're abstracting your, your security Secure microprocessor that a hardware vendor has specifically created to be secure, and then you put this third party insecure thing in between it. It looks like it simplifies things, it looks like it solves things, but it just, it just moves the goalposts to another spot. So it- The, the amount of, failure that can occur with some of these things is, is mind-boggling, and, we do the best we can, things aren't difficult, on the hardware side, but once, once you connect it to that device with unlimited resources, then you have to be extra diligent, from a hardware perspective."
    },
    {
      "speaker": "stephan",
      "time": "38:17",
      "start": 2296.64,
      "text": "Yeah. Salvatore, anything to add from your side?"
    },
    {
      "speaker": "guest_3",
      "time": "38:20",
      "start": 2299.56,
      "text": "yeah, I, I don't fully share the, the concerns about the, the, the USB. Like, I do agree that, there are some concerns, like for, for example, differential power, power analysis is something that did happen in the past, and it caused also some vulnerability in different devices, But, the point of view is that, well, from the point of view of the constr- of, of the vendor of the, of who's making the hardware, there is an easy solution to the, the complexity of USB, which is, you connect the USB to some simpler thing, for example, a simple, a simple MCU that isn't, so you don't con-connect directly the, the USB to the secure element which con-contains the, the keys, and so this MCU Basically can be considered part, part of the untrusted world, meaning, from the point of view of the other components of the hardware, even if the software somehow, exploits USB to try to, take control of this MCU, they didn't, still don't have control of the device because, for example, the, the screen isn't controlled by this MCU, but is controlled by the, the secure element, for example. So this is, the, the concerns with MCU, I think, can be, addressed from, from the point of view of the constructor. And, my point of view is that, it's quite limiting to try to do everything air-gapped, because it prevents you from doing a lot of interesting, useful things that, can actually im-improve the user's security. and, and so for example, one of the things that becomes, very hard to do Is what if you want to do a multi-sig between your hardware wallet and your so-- your software wallet or some other, online machine, right? so this, in a regapped mode, it's, it's a lot harder to do, and it has some, some interesting use case, especially if you want to do something like multi-sig, which is a two-round protocol where, you have to, call both the signers multiple times. And the reason I'm a lot interested in these kind of, applications is that, i-i-in a context where we are, we are able to program, our software wallets a lot more thanks to something like Miniscript, this has a lot of interesting, li-in-interesting use cases, including also, fixing in a much more general way the kind of problems that, that, Antaeus will try to do with, for Dark, Dark Skippy."
    },
    {
      "speaker": "guest_3",
      "time": "40:35",
      "start": 2435.43,
      "text": "I, I, I did a, a I'll give you the link, which tries to, analyze this, kind of attacks in a, in a much more general way. And the point of view is exactly this that, like you can't, do this kind of exfiltration attack if you have a multisig two of two, because now you need to do that on each single device, right? but if without miniscript, if you just do a multisig between your hardware wallet and your, and your software wallet, well, that kind of breaks your security model, because now, for example, the software wallet could- could destroy the private key, the hot key, and lock your funds out, for example. This is something the hardware wallets don't want the software wallet to be able to do. but in a world where you have Miniscript, you can use this hot key as an additional key, so it's strictly incremental, security in terms of, spending. but then thanks to Miniscript, you can have additional spending policies that become available later for recovery where you don't have the hot key. And so the point of this blog, blog post was exactly"
    },
    {
      "speaker": "guest_3",
      "time": "41:39",
      "start": 2498.88,
      "text": "Hopefully, this kind of policies, you can actually create, software wallets that give a user interface which can even be very similar to the one of a single-signature wallet, but it protects from a much bigger class of attacks."
    },
    {
      "speaker": "stephan_livera",
      "time": "41:52",
      "start": 2511.69,
      "text": "You, you know, I, I read your, your blog post, it was actually really good. so the, the, the main issue is that like the, the current state of the market, right? I, it's more like, like just from practical perspective, y-you know, MiniScript is fairly new, right? I mean, you know, we were trying to push output descriptors for how long? You know, there is wallets in the market that still don't even support PSBT, right? Like, i-if we talk from just like sort of,"
    },
    {
      "speaker": "stephan_livera",
      "time": "42:22",
      "start": 2542.21,
      "text": "The major, like some of the major, devices on the market, like they, they don't have a separation between their MCUs and USB, right? They talk directly, they use the UART on the MCU. and then you have devices like, say for example, Jade, where, you know, this, this is the ESP32, it's a fantastic sort of Chinese, device from Expressif, lots of memory, lots of cool stuff, not designed for security, right? And, and the USB is like, you know, straight in there, So, you know, they, what they did is they added the, the pin server, which is brilliant, like, you know, but now your security, your hardware wallet needs to talk to a server in order to sign something, which, you know, again, all depends on, on sort of like your preferences, and, you know, the majority of the market is still on single sig, single sig plus, passphrase, right? And, and we should recommend that most people use passphrase if they're on single sig, but, you know, not everybody's gonna get there So I, I, I do agree with you that, you know, once we see the majority of the people moving on to miniscript again, multi, multi-sig or, you know, like forms in which a single device is de-risked, then absolutely, right? Like, you know I, I do see then not being as much of a risk of having a device connected, but, you know, if you're using single sig, you know, like, I, I don't see a safe way for most of the platforms in the market to, to be connected to USB. Like, i- it's just a trade-off that, you know, doesn't, like, it's impossible for me to get over. And, you know, I, I do, I do sort of like respect the, the, the ledger security that he, that he has because of the choice of platform on how he does USB. but that's like, that's one device of the market, right? Like every other device in the market is, is doing, you know, essentially like MCU-based USB. a-and, and, and that's why I guess, like, you know, I'm so intense, let's put it this way, mildly, on Twitter about people not- Connecting things to USB, it really is brutal. a lot of these devices are simply not secure enough for that. and, and, you know, and bugs happen, right? And if bugs happen, you know, money gone. that, that's sort of like, like my, my mental model for this stuff. I don't wanna be fair to the"
    },
    {
      "speaker": "guest_2",
      "time": "44:50",
      "start": 2689.87,
      "text": "Jade device, don't they? I think they use a, an external, USB serial chip It's, it's,"
    },
    {
      "speaker": "stephan_livera",
      "time": "44:57",
      "start": 2696.87,
      "text": "it's ESP"
    },
    {
      "speaker": "guest_2",
      "time": "44:57",
      "start": 2697.29,
      "text": "thirty-two. It's the package for the USB. I'm gonna double-check that, 'cause I, I, I could swear they use an external USB interface rather than the ESP thirty-two. I, I believe the ESP thirty-two"
    },
    {
      "speaker": "stephan_livera",
      "time": "45:05",
      "start": 2705.18,
      "text": "might have, in the package a UART sort of like, a bridge, but it's all part of the same package, right? Like, there is no-- You can, for example, flash the, like, you can run arbitrary code on, on a ESP thirty-two, the, the K ten"
    },
    {
      "speaker": "guest_4",
      "time": "45:26",
      "start": 2725.79,
      "text": "Go ahead. Without getting too much into the details of the, the Jade, because we could spend a whole lot of time talking about that, one of the, the biggest differences that I see between, USB only hardware wallets and those that follow more of an air-gapped route Is that the USB ones generally have a proprietary protocol to talk to the hot hardware wallet, and by that I mean, not, not that it's a, a pro-pro-pro-pro-protocol which, which can't be kind of, known, but it's more one which is unique to whatever vendor is putting that hardware wallet forward. And that means that you are far more dependent on that vendor going forward. You know, from the point of view, if you have a air-gapped device That is using, for example, U R or barbecue QR, QR codes, or just straight PHBTs, which are shuttled back and forth with an SD card. You really have a standardization there which is far more, than you have with a USB hardware wallet, which, as I say, is using a proprietary pro-pro-pro-pro-pro protocol. Now, they are, luckily open source or at least, you know, open in the sense of, Third party interfaces that you can use, and we're lucky to have Ava Charles HWI, which does a lot of that work for us. But for me, it's, certainly feels less secure from a, a kind of, is this thing gonna work in ten to twenty years, than if I have a standardized protocol that, you know, is being written up and kind of has been implemented in- Many different devices, or different software packages, you know, then I kind of know, well, if, you know, if Sparrow isn't around, we've got other ones, you know, we've, we can rely on that. Whereas right now with the USB hardware wallets, you either use the vendor-created software package or you use HWI or you might have an integration, which is unique to a wallet, for example, like Electrum has. You know, that's kind of-- but it's a, it's a, from my point of view View that's a more risky approach, because you just have fewer kind of people working on that bridge because that bridge is a proprietary bridge, it's not an open standards compliant bridge."
    },
    {
      "speaker": "stephan",
      "time": "47:55",
      "start": 2875.47,
      "text": "This show also brought to you by Nomad Capitalist. Nomad Capitalist is a leading provider in terms of offshore tax and lifestyle strategy planning and implementation. They can help you go overseas and legally lower your taxes. As many of you know, I grew up in Australia, but I left. I was six Think of it in terms of the taxes and the COVID tyranny and all these other things. And so that's why I left, and now I live in Dubai, but that's not necessarily the place for you. You have to think exactly what works for you, for your family, for your business. And Nomad Capitalists have worked across dozens of different countries. They've helped people get passports, residences, bank accounts, and all kinds of other things. And importantly, it's not just about choosing one place, it may be multiple places, and it may be also about making the pieces fit together in terms of You as an individual, Nomad Capitalists have helped many, many people in terms of going overseas, and if you're interested, go to nomadcapitalist dot com slash apply. This is applicable for people with a net worth above one million US dollars. That's nomadcapitalist dot com slash apply. And now back to the show. I see, so it's a point around, let's say redundancy and being able to recover in the future, let's say five or ten years down the line, maybe certain things don't have support anymore or- Maybe, you know, in that example where it's like a specific vendor, software, maybe what if that ven- what if that manufacturer's not here anymore, right? Like, so these are some of the reasons why this kind of redundancy, concern is a legitimate one and kind of having these open, standards and open ways of doing things perhaps is, preferable. But, you know, it's also understandable that s- v- different vendors and manufacturers may wanna differentiate themselves and may wanna offer more features, so this kind of- There's always gonna be maybe a bit of a tug of war there until something becomes standardized enough that everybody uses the same thing, right?"
    },
    {
      "speaker": "stephan_livera",
      "time": "49:50",
      "start": 2989.95,
      "text": "I mean, remember pre-PsBT world? You know, like I, I remember in those days, you know, like we, we had a, a multisig, before BigO was kind of the same thing, and, you know, like we, we integrated Ledger and Trezor, and this is like over ten years ago, right? and, you know, we wanted to have like hardware wallets compatible, and, and, you know, we wanted to make hardware wallets, but like we were like, we're not gonna make a custom USB spec, for, for hardware wallet until we found, you 124 from HL abandoned there. And, you know, we, we built because of that, like because that bit essentially created a standard for, how wallets and hardware wallets sort of exchange, information for signing, right? in my, in my opinion, that's sort of like, you know, indispensable for how a hardware wallet should- Like every single part of the stack in Bitcoin should be completely vendor independent. that, that's sort of like my personal opinion on this. Like, y-y-y-y, you know, we have an open protocol, right? There is no reason to, to do a thing that isn't sort of capable by every other device. A-and so you can just, you know? Craig with Sparrow shouldn't even care or know which hardware wallet you're using, ideally, right? That, that is the goal in, in my opinion, because, you know, maybe I created a seed on one wallet and then I don't like it anymore, or, you know, I move it to another one. Like nobody should care which hardware wallet you're using, and nobody should care which client wallet you're using either, right? These things should be completely independent because if you don't know Which hardware you're using, the attacker has a lot less information, to, to attack you. I, I think that's like a, a huge information asymmetry advantage, for, for the signers."
    },
    {
      "speaker": "guest_5",
      "time": "51:44",
      "start": 3104.48,
      "text": "Yeah. So something that isn't talked about too often is, is synchronous communication between an external device. So this is something that, If you think back of how the device can be updated with that malicious software, okay? Usually it'll come over the way that the, the vendor tells the user to update the device. If you're using an SD card, maybe it'll come over SD. If it's using USB, it's probably gonna come over maybe USB. The advantage of something like an SD card is that All computers can read an SD card, and all of it's there for you to see. I, in a trusted SD card is what we're assuming here. and it's more likely to have a trusted SD card than some of these other, specific hardware wallet things, in my opinion. But It, it's slow to move software from an SD card to a device. The advantage you have is it's inspectable. The user can inspect it maybe one day, the next day they could load it on their device, they have time between whenever the, whenever the, information is written to the card and whenever the unit is updated. During that time, you can check Twitter, you can check the vendor's website, you can check email, you can, you can talk to people. There, there's time that's, that's built in there. The problem with USB is it's instant and it's invisible. The user can't inspect what's happening, what's being communicated. So there's a level of trust there that makes me uncomfortable. and there, and there's ways you can do that with, with trusted client-host, communications and, and custom things like Craig was saying. but it, it still That comes back to the, to this fallacy of having such, such a thing as an air-gapped device. There is communication that's necessary, and if the communication gets too complicated, it's gonna be harder for the user to, To use that, and they'll start making compromises themselves that you don't expect as the vendor. Yeah. You know,"
    },
    {
      "speaker": "stephan_livera",
      "time": "53:34",
      "start": 3213.51,
      "text": "a, a good way to think about synchronies in, in an attack is, you know, if you're a programmer, i- imagine like trying to enter something without logs, right? Like try to fix a program without checking the logs, right? That's a level of synchrony you have when you're trying to do something. you, you know, now try to sort of break into something without having an immediate response, you know, showing like what's happening, you know, in feedback, and, you know, this sort of like goes to sort of, it's a good way to, to sort of understand this synchrony that we talk about when we talk about like USB attacks and no USB attacks, you know, aside from, you know, all the other aspects of it, you, you know, having direct access to something is very difficult and very- Different than having indirect access to something. you know, it changes the level of, of sophistication, right, that you need in order to get in there. I mean, sure, stuck net is a possibility, right? But there is a reason why those nuclear plants, you know, aren't connected to the internet or aren't connected to other things. It's because we wouldn't have heard the story if"
    },
    {
      "speaker": "guest_5",
      "time": "54:43",
      "start": 3282.52,
      "text": "it was, yeah."
    },
    {
      "speaker": "stephan_livera",
      "time": "54:44",
      "start": 3283.62,
      "text": "You know, one of the first things you do when you have something important, important is not connect to anything. You know? it, it does remove some, some UX things, but, you know, at the end of the day, i-it's, it's a very reasonable approach to security, right? because again, we, we just don't trust the, the, the stack, we don't trust the, the USB,"
    },
    {
      "speaker": "stephan_livera",
      "time": "55:09",
      "start": 3308.95,
      "text": "spec. Gotcha."
    },
    {
      "speaker": "stephan",
      "time": "55:11",
      "start": 3310.51,
      "text": "One point I wanna pick up on, and sort of related, I think ADD or Add BTC, you were mentioning this idea of inspectability, and I think one question that comes up in my mind is to what extent? Is the community relying on social security, right? So because, you know, you could be a total noob who's left your coins on the exchange, and maybe you've got a single signature hardware wallet, you have no idea what a passphrase is or multisig, and then, you know, as you kind of advance up, and now at the sort of extreme end, there's those really paranoid users who are checking everything, maybe they're reading code and they're verifying things. Hi-hypothetically, there's someone out there who's, you know, building hardware wallets from scratch if they can, Are there any comments there on how, how much trust is kind of the ecosystem placing on, let's say, those ultra-nerd users, to go and actually do the inspecting, as that example, right? If, if, you know, in the SD card example or any, anything like that?"
    },
    {
      "speaker": "guest_5",
      "time": "56:10",
      "start": 3370.05,
      "text": "Yeah, that, that's the trade-off. It's kind of the trade-off of, automatic updates, right, versus manual updates. Do you automatically update the user to protect them, also introducing this path of, of risk, right? So that if your automatic update processes are commandeered by some malicious actor, that they can get in there and do all sorts of bad things, or, or do you let the user do that themselves? And I, I think there's, there's arguments for both sides."
    },
    {
      "speaker": "guest_5",
      "time": "56:39",
      "start": 3399.05,
      "text": "I, I would hope that people are, are listening and looking, at, at other trusted people to, to kind of help them in some of those, communications of problems, but, but I don't think that's something that would ever be, adequate or sufficient. again, if you, if you make it easy for the user to do that, the user will do it more often, and maybe in those times when they're moving Large quantities of Bitcoin or maybe in the times that are the most essential or the times when they do that, and then there's other more, more, e-either easier UX or less trusted ways that they can do that, like, like a phone wallet, for example, where you just assume everything's working and you just go for it. So yeah, I, I don't think I really have too many opinions on that. I, I think having the option to do it, a-and again, going back to, I mean, what I wanna see is this ultra-paranoid hardware maker myself, I, I wanna have these options. I wanna be able to do that when the time arises or if I need to. And the more options I have, the, the safer I feel, and I can confirm that myself, trust. If as few people as possible and, and to validate those things. but I, I think again, this is probably why that multiple devices exist. We have lots of- Hardware vendors, we have different users, different needs, and I, and I think that's a, that's a good thing to have those options in the, in the community."
    },
    {
      "speaker": "guest_4",
      "time": "58:02",
      "start": 3481.96,
      "text": "Yeah, I mean, I, I think, you know, the whole of Bitcoin isn't a some abstract technical protocol which just kind of exists apart from, you know, humankind. It is a, it is a social process as well. you know, we could look at all kinds of areas of Bitcoin and say, \"Yes, you know, we require humans here, otherwise this thing just...\" Won't work. I mean, what if we didn't have people who wanted to mine? You know, what, what if, you know, there's all kinds of different levels to which this is a social process that we're in, and absolutely part of that social process is people checking things and making sure that security as designed is actually implemented and in place, you know, sure. NVK could decide to implement dark Skippy, you know, would someone find it likely? Would that be the end of his business model? Absolutely. Does that make- The game theory of doing it very, dis-incenten-central, central incentivized, I think so. Yes. So, you know, I think that these, these things absolutely need to exist, do exist, and are part of Bitcoin as we know it"
    },
    {
      "speaker": "stephan_livera",
      "time": "59:14",
      "start": 3553.5,
      "text": "You know, like, and when you put this in perspective, right? Like, you know, the, the device is, you know, verifiable, right? So like, all the source code is there, right? The, the, the chips on it, so the MCU, the secure elements, you know, everything that is there could be purchased from, say, DigiKey, right? the device is, is clear case. The, the, the device comes in a secure- Your bag. you know, w-when you think about like the amount of steps and people involved in, in order to either do like a, a, a general attack in the whole sort of user base would be nearly impossible, right? Because, you know, we're shipping like hundreds of thousands of device and the device is like, you know, one appears there, like, what? Because people do check. Contrary to what, like, Twitter thinks, it's like, we do get emails when there is updates, like, \"Why did you change this?\" but- You, you know, a general attack would be ne-nearly impossible, right? So, you know, you'd be targeted, targeted attack. Now, okay, great, like, you know, we don't know who you are, right? To receive, and now I have to like convince like a bunch of people in my, within my organization, right? And, and in the supply chain in order to like, like, send a device that has like, evo code that, like, I don't even know where I'm gonna stick it, 'cause if there's not enough memory. But"
    },
    {
      "speaker": "stephan_livera",
      "time": "01:00:42",
      "start": 3642.68,
      "text": "Saying that, that like, you know, it's just, it's just unrealistic, right? Like, and, and yes, we do need solutions to, to make sure that there is a proof, a cryptographic proof to it, yes, but like, the practicality of some of these attacks are so absurd that, like, okay, we have time to come up with a great solution, we don't have to freak everybody out. who are safely right now, right, to go and touch their devices, they're secured somewhere and maybe get robbed or, or, you know, accidentally do something, because they're now in haste because some guy on Twitter said that like this is the worst thing that could possibly happen, right? Like, the, the perspective in these things is very important."
    },
    {
      "speaker": "guest_2",
      "time": "01:01:26",
      "start": 3686.47,
      "text": "I think you got really close to something that I've been wanting to mention in this talk, which is the idea of trust on first use or, or TOFU security, and, and any device out there with a secure element and, a signed upgrade process, whether that's Ledger or Coldcard or BitBox or, many of the others as well, gets pretty darn good trust on first use security if you get a good device from the manufacturer and you don't let it be in malicious hands, it is very, very difficult Difficult for anybody to have even the chance of getting malicious software onto that device. And that's, I think, the strongest thing we have going for us, frankly, in this Bitcoin security. And it goes back to your point, NVK, of we don't want people running out and upgrading devices because now they're having to retake a trust leap. They've already got a device that has good trust on first use security in their hands. Don't go buy a new one and switch over, 'cause now you've introduced a new trust step that you didn't have before. you-- So It's very nice with devices that have signed for, for more updates, that you get trust-- sorry, you take a trust leap when you buy it, and then if you've gotten a good device, which you very likely have, that trust now holds you forward as long as you keep using that device."
    },
    {
      "speaker": "stephan_livera",
      "time": "01:02:35",
      "start": 3755.04,
      "text": "You know, just for perspective, right? Like You know, it hasn't been demonstrated to us, even with our first device that only had one secure element in way back then, that, an attacker is capable of running arbitrary code without the user knowing Okay, like that, that hasn't been possible, right? Because we have the green light that checks for the user, right? And if the, even if the user blasts some custom firmware he wants to run, it still at boot shows you a message saying, \"Hey, this firmware isn't signed by factory,\" right? So, you know, when the, the good folks from Donjon, managed to see the extract from, Mark III, They still not able to run arbitrary code in there, right? Like, and, and that, like removing the seed in the way that it was, it was one thing, right? And costed a lot of money to do it, and the risk of destroying the sample, and, you know, all the, the, the, the caveats on, on that attack, which was very cool, by the way. The, but they're, they're still not capable of changing the secure element in a way that would allow them to stick, you know, their own keys in there Arbitrary code. That isn't true, right? For a Raspberry Pi or a, ESP32, for example, right? Like those devices can't run arbitrary code because they can't secure their boot. Right? Like so, th-there, there is a lot of nuance in this, and, and, and it's nearly impossible for a civilian, right, to, to understand the complexity of hardware. I mean, like, heck, like, you know, by some of the comments of even some core, Bitcoin core developers, on this attack, I mean, they missed the point of how the hardware actually works. So I, I, I think, I think the, the biggest take from this whole thing is like, you know, please don't freak out and go touch your Bitcoin because you're gonna probably lose your Bitcoin because you're freaked out. Don't, don't freak out is always rule number one, right? a-and, and then let the dust settle and, and then you can sort of figure out like, okay, do I need to learn how to code to review code or do I trust a little bit or like, where do I go from there? You, you know, let, let And, and, and that's the beauty of having so many devices, right? Like everybody goes at each other's throats, as soon as, as soon as there is something new to, to-- for a lot of bored, technical people to argue about."
    },
    {
      "speaker": "stephan",
      "time": "01:05:03",
      "start": 3903.67,
      "text": "Great, well, I think we've probably, should start to wrap up. So let's just, take it from here with, final comments. If you have any thoughts on how to contextualize this and maybe what, what, what are some of the things that you'd like to see in Bitcoin security in the short and medium term? Any, any comments?"
    },
    {
      "speaker": "guest_4",
      "time": "01:05:21",
      "start": 3921.17,
      "text": "Yeah, I'm happy to go first. you know, I, I just want to kind of go back to what I was saying earlier. when we design products, and, you know, I see myself my skill primarily as a product designer, that's what I do. you know, you have to look at the entire user experience when you try to design a product, and that's not just the security of the product, but how, you know, what is the privacy perhaps that it offers, how easy is it, is, is it to use? You know, you have to kind of look at the entire package, and I think it's important when designing any product to kind of see it from a holistic point of view, not to try and maximize one of those, those, those things. so I can understand, for example, why the Bitkey, for example, has gone for a device without a screen. It's not necessarily a device that I think I would like, like to use, but I can understand the design decision behind it, and, that's kind of my thinking. And what I approach is not to try and take a specific vulnerability and then say, \"Well, we have to fix this because security is the only thing that's important.\" Yes, we should try and fix it, but we need to consider what is the impact on the user flow. Is this actually gonna make the products usable or is it gonna just mean that nobody actually uses them? That's kind of the way that I would like everything to be viewed, that kind of more holistic lens."
    },
    {
      "speaker": "stephan_livera",
      "time": "01:06:48",
      "start": 4008.15,
      "text": "You know, the, the big key team like actually consulted with us and, and a few other people in the, in the beginning of the design, and extremely competent people. one of the people who designed their little protocol of how the keys go around, is, is a regular on, on Twitter, he's just sort of like, a known about it. and, you know, it's like- Their intention was never to create a, a device that is like, you know, state proof and, and, you know, like it's for you to have your, you know, your quadrillion dollars of Bitcoin. And no, it was like, hey, let's make something that's extremely easy for people that don't mind some privacy trade-offs to come onto Bitcoin and hold Bitcoin securely enough for that set of trade-offs, right? Like, and then maybe they move on to other, like- More secure pastures or, or more private pastures, depending on like what they're, what they're seeking, right? Like, w-we need people doing that. We need like companies like Ledger spending a lot of money trying to bring in new users. Like, w-we need this stuff, right? But like- And, and we don't wanna like completely like shock these people coming in with like, \"Oh my god, you are vulnerable to a nonce attack, \" you know, when they have like zero point zero one BTC, y-y-you know what I mean, like on an unfairly secure sort of environment. It's- The conversations are important and, and you know, we should have them, but, you know, it's, there is a place. Go"
    },
    {
      "speaker": "guest_3",
      "time": "01:08:22",
      "start": 4102.64,
      "text": "next. So just to close on the, entire, anti-XV and, and Dartski P, situation, I think the, the goal of making, devices that are fully trustless in the sense that, that the software wallet can, check for every operation that the hardware wallet, the hardware signer does, that the hardware signer is doing, what it should do according to specifications, right? So that's from seed generation, from si-signing, deriving the xPub's, everything that you ask the hardware- Device to do, right? so the goal of being able to do every of these steps in a trustless way, it's a very interesting goal and we should move into that direction. so Anti-X will, does that only for one of these interaction, interactions, and so far it's, it seems that, we will require some f-form of zero knowledge proof on the device to be able to do that for all the other kinds of interactions, right? but maybe who knows, maybe in three, four years, zero knowledge proofs will become so fast that And then at, at that point it will become, interesting. until that time, what is practical today is to use multi-signature, to use miniscript, so the practical solution that people can actually do to, to sol- to solve this problem for themselves is to use multi-signature miniscript. So let's make the, the user interface of multi-signature miniscript better and get more users to use them."
    },
    {
      "speaker": "stephan_livera",
      "time": "01:09:50",
      "start": 4190.16,
      "text": "I feel like I have Rob on the show here chilling miniscript. I,"
    },
    {
      "speaker": "guest_2",
      "time": "01:09:56",
      "start": 4196.22,
      "text": "I want to say, I think we've hit on this in this talk, I don't wanna say it very explicitly, the, the best hardware security device for your Bitcoin is the one that you have and use. And so the right one for any person is going to be different, 'cause some people have only thirty dollars to spend on a hardware device, in which case, Casa's new cool keys might be a good way to go, because it's, you can buy a UBI key for thirty bucks. If You might buy something else, you have to get something and you have to use it for it to protect your funds. A-and so everyone has a different UX they can handle, a different, a different cost they can handle, and, and so like any of the reputable vendors that we've talked about, if you can have it and use it, you're way ahead and probably good enough for a long time"
    },
    {
      "speaker": "stephan",
      "time": "01:10:40",
      "start": 4240.61,
      "text": "Add BTC. Anything else to add?"
    },
    {
      "speaker": "guest_5",
      "time": "01:10:43",
      "start": 4243.39,
      "text": "Yeah, I just think I wanna reiterate that, not to be afraid of commercial wallet vendors. I think there's incentives that work in your favor there, kind of like what Reardon is saying. You, you have the ability of oversight and, and commercial interests that work in your favor, and there's some vendors that are obviously better than others, try to figure those out, ask people that know what they're talking about, and then always look for signed updates. That, that is an essential feature that mitigates so many things that it's hard to even, Start to list them all, but, signed updates at minimum, and then the, the ways you communicate, that's, that's all secondary to those signed updates."
    },
    {
      "speaker": "stephan",
      "time": "01:11:24",
      "start": 4284.79,
      "text": "Fantastic. Well, I think it's been a great panel, we've covered a lot of stuff. we'll close it off there. So every, thank you to all the guests, and I'll put all the links in the show notes so listeners can find you guys. So thanks for joining me."
    },
    {
      "speaker": "guest_3",
      "time": "01:11:37",
      "start": 4297.54,
      "text": "Thank you. Thank you."
    }
  ]
}
