{
  "episodeId": "SLP748",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "craig_raw": {
      "name": "Craig Raw",
      "role": "guest",
      "tag": "CRAIG"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:00",
      "start": 0.0,
      "text": "Hi everyone, and welcome back to Stefan Lovera podcast. Rejoining me on the show today is Craig Raw, the founder, creator, developer of Sparrow Wallet, and, you know, Sparrow Wallet is an excellent wallet Basically my favorite desktop, app for Bitcoin, and, yeah, Craig, welcome back to the show. I know there was some recent drama on your account for the Apple developer situation, so let's chat a little bit on that, what's the latest there? As I understand, your account has been reinstated now, so you're not at risk of, you know, Sparrow not being available for Mac OS, right?"
    },
    {
      "speaker": "craig_raw",
      "time": "00:36",
      "start": 36.0,
      "text": "Yeah, thanks, Stefan. Really great to be back on the show. yeah, so there has been a bit of drama this week, very, unwanted drama to be honest, I think from all parties involved, that, I received a what I think was the result of like an automated process, at Apple. regarding an, an, unpublished app that I put out, what, tried to put out a year ago, and I think some kind of automated, process came along and said, \"Well, this app is just a placeholder,\" which it was, and, then said that they were going to terminate my Apple developer account, which means, as a developer, that you can no longer publish applications for any Apple platform, including Mac OS, in a way that allows them to be installed without- Bypassing a whole lot of security protections that Apple puts in place. So that was obviously very non ideal, given, you know, what a wallet is, you definitely want to not be bypassing security, safeguards in order to install any kind of application related to Bitcoin. It's just not a good, not, not a good thing to be doing. So, That was obviously, needed to be dealt with. Apple's review process, is a little bit opaque, so in the end, I kind of had to, take that off to social media because, the The deadline was drawing near, and I didn't want, it just to fall into this kind of void where people suddenly started to encounter these warnings when they tried to install Sparrow, and they're like, \"What is this? You know, is my wallet hacked?\" This kind of, kind of thing. So, that, has resulted, in my account not being flagged for termination anymore. So that has now been successfully passed, and, hopefully we will be in a situation- situation in the future where that's not gonna happen again. However, the issue still remains that we have these scam apps which appear on the iOS App Store, and there have been no small number of people who have very unfortunately been, taken in by these scams and who have lost money to them. so, you know, there is no Sparrow Wallet mobile app, And you know, that's, that's just the way it is. you know, there, there could be one, but then there would probably still be scam apps on the app store, and people might still be getting scammed. So there's no real easy solution to this other than Apple ensuring that there aren't any scam apps. Like that is just the only way to ensure that the app store is safe. hopefully with this latest incident, we are in a better place, and hopefully, Sparrow is more high-profile to them now, and we have a lower chance- Chance of these scam apps in future that remains to be seen."
    },
    {
      "speaker": "stephan",
      "time": "03:33",
      "start": 213.0,
      "text": "What lessons, can, you know, we take if you're, let's say, a listener is a, an app developer, a Bitcoin app developer, is there anything they should think about here?"
    },
    {
      "speaker": "craig_raw",
      "time": "03:45",
      "start": 225.0,
      "text": "yeah, I, I think, look, you have to realize if you are developing for Apple platforms, that everything you write is effectively within their walled garden. And the thing about a walled garden is that it is their right to take away your access to that walled garden. you can hate that, you can love it, you can decide not to develop for them, whatever you wanna do, but I think you have to realize that fact. that is a very fundamental fact. and that's, you know, not true, of, you know, Linux. so some people will say, \"Well, therefore, you should just only develop for Linux.\" I personally don't hold that view. I think you have to, my, my general view around application development is that you only really create meaningful change if you target as many people as you can. You have to try and be inclusive. You can't just say, \"Well, you know, I don't like this and I, I don't like, like that,\" so I'm gonna narrow Down to only the stuff that fits my particular point of view. now of course, I don't like the fact that Apple can, simply take away, my ability to write Sparrow Wallet for a huge number of people. I, you know, I'll be the first in line to say that I strongly dislike that, but it is a reality, it's a fact, and it's probably not gonna change."
    },
    {
      "speaker": "stephan",
      "time": "05:08",
      "start": 308.0,
      "text": "Yeah. And like, it just exposes this whole trade-off, right? Because look, as, as you mentioned, there's this platform risk on App- Apple, but at the same time, how many hundreds of millions or billions of users are there in the Apple ecosystem, whether on the iPhone or on the Mac, laptops and desktops, and I guess it's kind of like PGP versus Signal, right? Like, yeah, of course, of course, a few hardcore people will use PGP, many of the maybe listeners of this a- of this podcast, but Signal is the app that went to hundreds of millions of people, so it's a similar kind of thing there. So it's kind of like this weird, have to find Accessible to more people so that we can get more people to use Bitcoin in the self-custodial way."
    },
    {
      "speaker": "craig_raw",
      "time": "05:49",
      "start": 349.0,
      "text": "Yeah, that's absolutely right, Stephane, and that really, I think well states, you know, my kind of whole approach to things is you have to be pragmatic in your, in your way forward. There are no perfect answers, there are no perfect ways to do things. You can't ensure that, you know, you can try and build on the best foundations that you can, you can control what is within your control, but how Apple decides to distribute apps is not within my control or within anyone outside of Apple's control, and we have to go where the users are, and we have to try and service them as best as we can there."
    },
    {
      "speaker": "stephan",
      "time": "06:27",
      "start": 387.0,
      "text": "Alright, so let's switch now to Silent Payments and Frigate. So for listeners who aren't aware, Silent Payments is, think of it like a new address type. You can just post up instead of putting a static donation address, you can post up a Silent Payments address. It looks like SP whatever, and it's like a string there, and- Some wallets have been adding support for this. Obviously, you, Craig, have added silent payment support to Sparrow Wallet. Can you just give us a bit of an overview, what's the experience been like for that? What are the users saying on, just using Sparrow, you know, using silent payments in Sparrow?"
    },
    {
      "speaker": "craig_raw",
      "time": "06:59",
      "start": 419.0,
      "text": "Well, I think particularly on that point Stefan, it's still very much early days. I think, Silent Payments is really at the very beginning of, being used. it, it, it hasn't b-been particularly usable up to, I think, the Sparrow wallet release, because effectively what Silent Payments does is it gives you this static address. So instead of handing somebody an address which they can only privately receive on a single time, you can hand them an address on which- Which they, which you can pri- privately receive as many times as you want to, and there's a new on-chain address every single time you receive funds to this static address. So, you know, it's a huge step forward for privacy in, but, but, but Bitcoin, but, the way in which it was done, i-in the past was very computationally intensive for the client, and as a result, we had these wallets which kind of started up and it all looked good, but then you came back to it after a- A few months and it just never synced again because of all the computational work that was required. So really, I think we are at the start of a new phase now where we have a different approach, and that's the approach that Sparrow is using. And as a result, I think we're gonna need to not only see people, you know, trying it out for the very first time in a usable way, but also this kind of needs to filter through the Bitcoin ecosystem that things have changed and it's now- Are a usable technology that, people should actually adopt. But I think I, I'd actually like to take a step back before we kind of get into the details of that, and I'd like to pose a question to you, What do you think the number one privacy issue confronting Bitcoin today is? I,"
    },
    {
      "speaker": "stephan",
      "time": "08:49",
      "start": 529.0,
      "text": "I mean, it's probably KYC, chain surveillance aspects of it, but I, I don't know, maybe is that one thing, is that a, is that a range of things? And then of course, static donation addresses is like a big one. I don't know, that's probably, yeah, I guess Yeah, I guess it's probably those are one and two, off the top of my head, like just the fact that a lot of people have to use KYC, which in turn implies chain analysis or chain surveillance firms and static donation addresses, which is a single address being used, and not only that, it's tying it to your real world name. So as an example, if I, Stefan Lovera, post out, \"Hey guys, here's my BC1, blah, blah, whatever,\" and publicly post out, people can trace that Both in terms of, you know, what, what, where those funds go later on chain, and then the donors can also kind of wreck a bit of their privacy too. So that's how I see it."
    },
    {
      "speaker": "craig_raw",
      "time": "09:42",
      "start": 582.0,
      "text": "Yeah, I think, I think that that's, that, that's a good, good, way, way to see it. But I, I would, I, I would actually, go a bit further there and say that, you know, I think it's a, it's a very, little talked about fact that, address reuse in Bitcoin is the dominant form of how people use it. And I think a lot of viewers of your show might be surprised by that, because a lot of them are probably- Because we're in this little"
    },
    {
      "speaker": "stephan",
      "time": "10:11",
      "start": 611.0,
      "text": "echo chamber, right?"
    },
    {
      "speaker": "craig_raw",
      "time": "10:12",
      "start": 612.0,
      "text": "Exactly right. So we are all using the right tools and we are sharing a new address for every payment and we are doing it right, but that's not how the world at large is using Bitcoin. So address reuse, and this is a fact, this is something we can see on chain, there's no denying this, it's not a debatable point, over seventy percent and climbing. Of payments are sent to addresses that have been used before, right? So, so address reuse is the default, it's the norm, it's what everyone else is doing that you are not doing, right? So, that for me is the number one privacy issue affecting Bitcoin today, and why is that? It's because it's the default, right? So What's gonna happen here is that as this thing climbs and becomes more and more and more, eventually it's just gonna become the norm that you have one Bitcoin address and it just gets reused over and over. And the problem with norms is before long they become the mandatory default. It simply gets enforced. So There is no way for you to ever have-- you literally have a Bitcoin address which is associated with your name, and that's it. That's your one for life, or you know, something along those sort of, sort of lines. And they won't-- if, if that comes to pass, and, you know, I think many of us have seen laws which talk about address reuse being somehow a illegal or prohibited."
    },
    {
      "speaker": "stephan",
      "time": "11:44",
      "start": 704.0,
      "text": "I think generating new addresses to be an illegal approach, correct? Correct,"
    },
    {
      "speaker": "craig_raw",
      "time": "11:47",
      "start": 707.0,
      "text": "correct. Yeah, so, yeah, so, so basically the idea of re- of, sorry, of, of creating a new address, right."
    },
    {
      "speaker": "stephan",
      "time": "11:54",
      "start": 714.0,
      "text": "As in the law would sort of force more and more people to do reuse instead of doing it the correct, you know, the privacy-preserving way. I guess, and I guess just to touch on that a little bit, my understanding is a lot of users, in some cases, they have a static dona- Donation address or not static, but they have a set, a donation or, receive address in the exchange. And so because that's like a known good address, they just keep using that. Or even when they're receiving from the exchange, they might do it like that. Or another one is instead of, before they send a large amount, they do a smaller test amount. And I think for these reasons of like anxiety around, you know, making sure you get the right address, they just use the known good ones. And then I think that's why this problem has persisted for some time."
    },
    {
      "speaker": "craig_raw",
      "time": "12:38",
      "start": 758.0,
      "text": "I think the third is that we have these very large apps, like all the, the top, you know, Bitcoin wallet apps on the App Store, the sort of Binance and the Trust, Trust Wallet kind of, kind of apps, they are following the crypto model, and the crypto model is very much an account-based model versus, the kind of Bitcoin address-based model. So they just say, you know, we're gonna do everything the same, and here's Ethereum, and there's your account, and here's Bitcoin, and here's your single address, and they just do it Right? Because as a Bitcoin community, we've never provided them with a different way to share a single address, right? So we can say that it's their fault, but what were they gonna do? Were they gonna develop a specific thing for Bitcoin? No, they just do it the same way because that's what their users expect. and I think- To blame them is just missing the point. It's just really, you know, we need to have done better. I think, you know, if, if we were to now--"
    },
    {
      "speaker": "stephan",
      "time": "13:37",
      "start": 817.0,
      "text": "So just before, before we move on, can we just, I guess the thing that comes to my mind is What about Lightning Address nowadays? Like, aren't, aren't we just gonna see a lot more people use Lightning Address now for smaller values and really all this on-chain stuff is eventually, as number goes up, right? It will eventually be less and less, what, what do you make of that?"
    },
    {
      "speaker": "craig_raw",
      "time": "13:57",
      "start": 837.0,
      "text": "Yeah, I mean, sure, but you know, I think the reality is a lot of people gonna want the kind of certainty and the finality of an on-chain payment. there's still a huge amount of it, I don't see Lightning becoming everything, and, you know, it's, it's, it's still, Lightning has its own issues which will take a long time to get into, as you know, capital gets tied up and all, all of that, that kind of, that kind of thing. I think, you know, I'm a layer one guy I'm looking at that and I'm saying, how can this be better? And I think, there's, if you improve layer one, you improve by default all the layers above, right? You, you, you know, you can then do a lot of other, other things. So I think it's very important for us to keep working on layer, layer one and making sure that it's as good as it can, can be."
    },
    {
      "speaker": "stephan",
      "time": "14:49",
      "start": 889.0,
      "text": "But what about this point that, like, as an example, I mean, obviously, in theory, yeah, I think, I think it's This on, on X, a little while back, where I was sort of saying, \"Well, is it eventually gonna be like larger amounts will just be multisig anyway? And currently, silent payments doesn't support multisig, so then it's kind of like, is it just in this weird limbo phase where because the lower value stuff will just be done using Lightning? Now, of course, in practice, in the background, there might be ARK, Spark, Liquid, whatever, but using Lightning as the, let's say, transaction, you know, that kind of last mile thing. And then for the very large stuff, people will be using multisig. So then, what is the, like, where is the, where are the places that people would even use silent payments? Are we talking about only things that are above that lightning threshold, but still below what people would do multisig for, or is it more like it's a step, it's a hop, you know, you use silent payments as like this hop, and then from there you send it into your multisig, like, what is that gonna look like?"
    },
    {
      "speaker": "craig_raw",
      "time": "15:49",
      "start": 949.0,
      "text": "Yeah, I mean, I, I think that the, the Basically, so the, the, the issue is that currently you can't send from a, an amount received on Silent Payments to a multisig address. but there's a very easy way to deal with that. You just send, a, an amount to a intermediate, ephemeral address, a truck, eph-TRUC, and then you kind of bounce that off immediately off to the multisig. So that's something which will get solved, and wallets will- Just handle it. So I, I don't, I don't see that as a major blocker. Yes, it's going to, cost a little bit more, I'll be honest about it, but it's not gonna cost dramatically more, and, ultimately the benefits of silent payments far outweigh that small incremental complexity, You know, if we kind of, again, take a step, step back, and we say, you know, where have we come to in term-- Where have we come from, sorry, in terms of wallet tech, right? We started off with single address wallets, so we have these wallets where you go and you do some randomization, you create this secret, and then you create a single address off that, and that was the way that Bitcoin worked for many years. years in the early days, and then someone said, \"Well, this is crazy, you know, we now have to maintain all these bags of keys, which, you can lose a single key, and you have to have software which does this. Is there not a cryptographic way in which we can make this better?\" And that was the birth of what we now call HD wallets. And HD wallets allow you through things like your, seed, seed words to have a single secret and to create as many addresses as you want to off that. And that was I think largely seen at the time that this is how we can solve this problem of address reuse. And address reuse is as old as Bitcoin itself. It was specifically mentioned by Satoshi in the white paper as this kind of unsolved issue that needed to be solved. That was a major privacy problem with the original design. So HD wallets were seen as the kind of answer to that, but I think, what they've really missed is that it becomes trivial to generate a new address, but what remains non-trivial, what remains quite costly, is sharing that address, and as you just mentioned, Stefan, having the counterparty validate that the address is actually correct, that it's going to receive the funds, because you can't pull them back once you've sent them. So as a result of HD wallets not solving that part of the, of the issue, we have a- Effectively not solved address reuse at all. We have prevalent address reuse today, and no hope of it actually im-getting better. In fact, if you look at the chart, it's actually getting worse. It's on an uptrend, and it's just gonna get worse and worse and worse unless we do anything about it, and we're gonna end up in a situation, as we just spoke about, where you will have a single on-chain address that will be connected with you, and that will just become, you know, the default, if not the enforced default. So We have HD wallets today, but I think we really have to, as a Bitcoin community, move to something else. And if we don't move to something else, that's the future that is gonna happen because that's what the on-chain data says to us, with an, which is just an un-- as I said, an undeniable, undeniable fact. So Silent Payments or SP wallets, in my view, is a good candidate for us to move forward from HD wallets, and we've had HD wallets for twelve years now, you know, thirteen years. It's all been in there a long time, and now we have to try and say, \"Well, is there a new address system, which is effectively what these things are? Is there a new wallet address system that we should be looking at to replace that because we've got problems with what we are using today?\" now when we had HD- Safety wallets come in, you might think, \"Well, I'm sure that everyone just welcomed it and it was obviously better.\" But the reality is it actually wasn't. There was a huge amount of pushback from the Bitcoin community at that time who said things like, \"You've now got a single secret protecting all of your funds. If you lose that secret, you've lost all of your funds.\" And of course, they were correct. You now have a single Xpub which reveals the entire transaction history connected to that, which of course is correct. But can we honestly say that HD wallets were a mistake, that we should have ke-stayed with the bags of keys? I don't think that anybody today is gonna seriously make that argument. I think that people are gonna say, \"No, actually, HD wallets were a step forward. Sure, they had these risks, and sure those risks have proven to be correct, but...\" On balance, and this I think takes us back to the pragmatic point that we were talking about earlier, on balance, we take the benefits and we say that they outweigh these risks. We say that on, on, on a, on a sort of taken as a whole, we say that this is a better wallet address s-s-system. Now, silent payments is again a new thing, and it's coming in, and people are, you know, somewhat surprisingly in my, my view, that actually it makes sense of pushing back and saying, \"Well, what about...\" This and what, what about that? You know, now we have to spend a little bit more if we send to a multisig address. I say, yes, yes, you do. But at taken as a"
    },
    {
      "speaker": "stephan",
      "time": "21:23",
      "start": 1283.0,
      "text": "whole, is it worth it overall? Is your point?"
    },
    {
      "speaker": "craig_raw",
      "time": "21:24",
      "start": 1284.0,
      "text": "Yeah. Taken as a whole, we now have a solution to this massive address reuse issue. And that's a really good thing. So you have to, and, and you're gonna see a lot of, pushback from the Bitcoin community against silent payments as we have already seen, even though to me it's like obviously better. But you're gonna see a lot of people inventing arguments and random things, pushing out, but that's normal, that's a normal ecosystem reaction to something new. you're gonna have to look past that and say, what is the bigger issue here? And the bigger issue here is massive prevalence to address reuse that isn't Increasing over time, and unless you do something about it, it's gonna become the way that everyone uses Bitcoin on chain in future."
    },
    {
      "speaker": "stephan",
      "time": "22:08",
      "start": 1328.0,
      "text": "Got it. So, yeah, I mean, I'm with you on the pragmatism point that it is, you know, on net, seems to me like a better thing, but there'll be some ecosystem upgrades needed around this, in various ways. so there's a few things. So firstly, it's also useful to point out the UX benefit, right? Like, let's say Craig Raw has a silent payments address and Stefan Laver has a Contact list, we don't have to ask each other for addresses anymore. I can just be like, in my wallet, oh, here's Craig Raw, send him some, whatever, send him some coin, right? so that's actually a big win. we should also remember that, right? It's not just the privacy win, it's also the UX win. So that might be interesting, as a way to, to sell it, to get it over the line."
    },
    {
      "speaker": "craig_raw",
      "time": "22:52",
      "start": 1372.0,
      "text": "Yeah. So I mean, I, I think, you know, where, where privacy and convenience come to conflict, privacy always loses. It's, it's a guar- guaranteed loss. You're never gonna win that battle. So you have to make a-- if you're gonna make a privacy solution, it has to be more convenient than the state-- status quo. And there's no question that silent payments is more convenient. It is certainly much easier to say, \"Here's a single address, you can pay me as many times as you want to,\" than say, \"Here's a new address, New one, and I think we all know, know this. We've all been through the pain of having to, you know, communicate with people who are less, Bitcoin savvy and get them to send us payments, and it's just painful, every single time. So certainly this is a major convenience upgrade for us all, to be able to adopt, adopt, adopt this. but, you know, It needs to actually, you know, get adoption in wallets. It needs to, it needs to have, and, and that will take time, it will take years, it will take a lot of effort and a lot of education, and people will have to gradually get used to the idea that there's a new way of doing things and abandon the old idea and get over some of the, the sort of hurdles and the down-downsides, you know, which will no, no doubt come along. that's, that's, I think, just part of the whole upgrade cycle We have"
    },
    {
      "speaker": "stephan",
      "time": "24:16",
      "start": 1456.0,
      "text": "to go through. So yeah, I mean, I'm with you on that in terms of using, you know, if you're doing on-chain silent payments is, you know, a pragmatic better step. But even pragmatically speaking, there may be a lot of people who just prefer to use Lightning Address for, you know, so I guess you, you, you will still have to have that battle between which is better, Lightning Address or silent payments, because that will be a real thing for a lot of people, especially, you know, at smaller values. So is it gonna be more like Larger value level that it actually is more pragmatic?"
    },
    {
      "speaker": "craig_raw",
      "time": "24:48",
      "start": 1488.0,
      "text": "yeah, look, I, I think, people will just use, use both. I don't really see them as-- I mean, I, I guess if they were both products and kind of making money and competing in a market against each other, then I think that that view holds. It's obviously not the case, they're not compete, they're not making money and run by different businesses, they're just different ways of doing things and we should-- Yeah. Different"
    },
    {
      "speaker": "stephan",
      "time": "25:10",
      "start": 1510.0,
      "text": "concepts, let's say. Yeah. Yeah. Let I know there might be some ways to kind of sort of hacky integrate them together, but it might be like, let's say I've got Craig Raw as a contact in my phone, I can be like, here's his home number and here's his mobile number, you know? Is it gonna be like that, where you might be like, okay, here's Craig Raw's SP address and here's his Lightning address for like the fifty cent payment, and obviously use his SP address for the larger value? Is it gonna be something like that or what are you thinking there?"
    },
    {
      "speaker": "craig_raw",
      "time": "25:38",
      "start": 1538.0,
      "text": "Yeah, so we actually have Mathematic, mathematic things, but there is a sta-stand standard, the three five three, I think, which is, basically allows you to have a DNS record which says, you know, I am Stefan Rivera at stefan rivera Podcast dot com, and these are my ways to pay, and that will have your silent payments address and your Bolt Twelve address in there. And the wallet software may give you a choice, or it may simply send the payment over whatever it decides is best. but all of that will be kind of hidden behind this thing that looks pretty much like an email address, and that will effectively be, hey, if you wanna pay me, just pay to this address."
    },
    {
      "speaker": "stephan",
      "time": "26:29",
      "start": 1589.0,
      "text": "It's all in one. Sort of thing. But even there, I'll tell you, I mean, I, again, I'm with you, and that is the process, right? That's where we're going. But, even now today, there'll be examples where I try to pay from one wallet to another, but then because one of them, one of those wallets is using, you know, the BIP three fifty three style and BOLT twelve, and the other is using like LN URL, and they can't read each other. Yeah. You know what I mean? And we get these kind of So it's sort of like to eventually get us, but I think I agree with you that that's kind of a, a good longer term, like that's where we're going. That's, that seems obvious to me that that's kind of, it has to be that way. but it's just kind of there are these teething issues on the way there, right?"
    },
    {
      "speaker": "craig_raw",
      "time": "27:16",
      "start": 1636.0,
      "text": "Yeah. So I mean, look, if you compare silent payments against Bolt Twelve, and again, I don't see them as competing really, but it, you know, Bolt Twelve is vastly more complex. I mean, Like, like, like, like, like, magnitude more in that it has to share information along this live network and all of these kind of, kind of things, whereas Silent Payments is very much a extremely simple cryptographic algorithm which has been reused in many different schemes in the past, so, you know, it is more likely that Silent Payments is going to be a simpler upgrade for wallets to make, and I can put it that way because it's just simply easier to implement."
    },
    {
      "speaker": "stephan",
      "time": "27:59",
      "start": 1679.0,
      "text": "So the other- Big trade-off, and obviously this is part of why you, you made Frigate, but let's talk a bit about this. I've seen, as an example, I believe his name's Jonathan, I can't remember his last name, is it Underwood? he gave a talk, he is, a CTO of a Bitcoin exchange in Japan, and he was talking about the scanning challenges, right? That there's a lot of the-- That's one of the big trade-offs, silent payments, is that there's a greater scanning requirement, You were saying it's insurmountable, but it is kind of, there is this, trade-off around, you know, you know, having, giving out all these silent payment addresses if you've got a lot of customers, as an exchange. So do you wanna just talk to us a little bit about this scanning problem and, and then maybe also go into a bit about, you know, your idea with Frigate?"
    },
    {
      "speaker": "craig_raw",
      "time": "28:49",
      "start": 1729.0,
      "text": "Yeah, sure. So I think, I think, yeah, that's a, that's a great setup. so if, if we look Algorithm that has been used by many schemes in the past, Bit 47 is one, right? It uses exactly the same thing. It's called Elliptic Curve Diffie-Hellman, it's very standard, it's been around for decades, there's nothing new about it. What is new about Silent Payments is that the way in which it arranges the information in the scheme, right? So that Bit 47 uses this, use this thing called a notification trans-transaction to put the data in a certain place. Silent Payments uses the actual transaction uses the UTXOs that go into it as the place to put similar information. So it's a rearrangement rather than something completely new. Now, what that means is that it's a much cleaner system in terms of sending, because now as the sender, you can just send to the silent payments address, you don't need to know anymore. But the complexity now falls on the receiver, and the receiver now has to do all of this computational work. and that's really the reason that why silent- Silent Payments, which was, you know, the, the book came into place, I think, you know, many years, years ago, that's the reason why it's been so slow to take off is because we've had this issue. So for me, when I started looking at this, I said, \"Well, unless you can fix this issue, this thing is just never gonna go anywhere, because we can have, you know, you and I can both run a server which does the computational scanning for us, but, you know, all the other people aren't gonna run their own server, Those thousands of people out there aren't gonna go home and set up their own thing. I wish they did, but they're not going to. So we need to have a way in which the masses can use this tech, and that's what I decided to try and address. So my goal was to create a public server, in other words, a server that could be run by somebody which could scale to do all of this computational work for everyone and do it for free, and that was effectively what I tried, tried to do. Now The, the challenges were quite severe. Now, i-if you had a single silent payments address, it could take you, as I'm sure many people have tried on their own devices, it could take many minutes, if not hours, to catch up your single address. Now, how are you gonna scale that to thousands of people using one machine? Way in which I did it was several different steps. So the first thing I did was I put all the data into a DB, a database, and then I said, \"We're gonna have a database function which can operate on that data as close to the database as you can, right?\" So no, that's a huge efficiency improvement between getting all the data out of the database and working on it there. the second thing I did was said, \"This is, A computation that we do on every single transaction, but the order doesn't matter. We can do it on the first transaction, the last transaction, the middle transaction, the order doesn't matter. So this actually turns out to be a problem that GPUs do really, really well. And if you are in the tech space, you've probably seen how all the applications are gradually moving towards leveraging, sorry, leveraging the GPU on your machine, which are increasingly getting more powerful, and AI is a big part of that story, of course. But, you know, from the text editor that I use today to the terminal that I use today, everything is starting to use the GPU because the GPU is this huge resource that is able to do a lot of computational processing and take it away from the CPU. So I said, \"Well, let me use the GPU, 'cause it's perfectly aligned to this particular task.\" So that was the second step, and then the third step was, was, was actually a different develop-developer who came along and said Look at these cryptographic algorithms, they're not optimized for GPU at all. I'm going to take that on, and it just came in at the right time, and this guy took these algorithms and made them again so much faster. Now, we had basically three orders of magnitude, three different steps, so we went from one X to a thousand X, and that made all the difference, right? And that, that's actually a very unusual thing. I didn't expect that to happen at the start of my journey in this. and I think it's, it's, it's important to realize that that stuff just doesn't happen every day. Usually, performance improvements in cryptographic algorithms are in the region of, you know, people get excited like ten percent is like a big result. That's like a published world result. A thousand x is basically un-unheard of. People don't really do that, in usual times. So I think it's important to realize that this was a really big movement from- Taking this algorithm which was effectively unscalable to one which, can could be run on a public server. Now as of today, we have a public server which has been running, up there Since the release of, since the last release of Sparrow, which was approximately a month ago, and it's running fine. And anybody can use Sparrow today, create a silent payments wallet, and use this server. And yes, sure, there are concerns around pub-pub And they can use Silent Payments today at zero cost, and it's, it's instant. It, it's-- their wallet will scan within seconds, even if they're scanning years or months, it will scan within seconds. So effectively, that computational burden has been solved on a public server level. Now, I still encourage people to run their own servers, absolutely, you know, but the reality is that unless you solve things for the vast majority, you don't create social change. You don't create a difference, you just create it for you and your pals. You don't create the default for what people use. What we need is for Trust Wallet to be using Silent Payments. When they give someone an address, it should be a Silent Payments ad-ad-address. That's how we see this address reuse number start to drop instead of climb. That's, that's real change, and that's what I've tried to work towards, So hopefully that gives an idea, and this piece of soft-software which does this is called Frigate. It's a electron so-server, and it effectively does this very fast GPU computa-putation. It can run on the CPU as well, so, you know, it's, it's, it's got optimized, al-algorithms for that, but, it really shines when you give it access to to a GPU, so like a Mac Mini has got a really powerful GPU built into it and it will run this really well."
    },
    {
      "speaker": "stephan",
      "time": "36:00",
      "start": 2160.0,
      "text": "Interesting. And so is this, is Frigate like a, a competitor then to Electrs or Fulcrum or, those, like the well-known Electrum servers?"
    },
    {
      "speaker": "craig_raw",
      "time": "36:12",
      "start": 2172.0,
      "text": "Yes, I mean, I guess, com-competitor is one sort of term, but yes, it It is. I, I, I hope that those, servers, take on the silent payments burden as well, of course."
    },
    {
      "speaker": "stephan",
      "time": "36:25",
      "start": 2185.0,
      "text": "So your hope is that they would also implement similar optimizations so that they can also serve up silent payments, addresses and information to the, to the clients, obviously."
    },
    {
      "speaker": "craig_raw",
      "time": "36:35",
      "start": 2195.0,
      "text": "Yes. So I mean, my intention with Frigate was never to, you know, I, I didn't have a particular desire to go out there and write a server. I just said it needs to be done, otherwise this thing isn't gonna happen. so, you know, that, that was my intent, and now it's out there in the world. right now it actually, it, it only does the silent payment stuff, and then you have to run either a ledger or a Frigate, Frigate, Frigate, Frigate, Frigate crew, and it kind of talks to that"
    },
    {
      "speaker": "stephan",
      "time": "37:01",
      "start": 2221.0,
      "text": "alongside it, yeah, okay, got it."
    },
    {
      "speaker": "craig_raw",
      "time": "37:02",
      "start": 2222.0,
      "text": "So that, that's, that's kind of an intermediate step in time it will do the entire, entire thing because the other parts are not very hard to do. I just, I"
    },
    {
      "speaker": "stephan",
      "time": "37:16",
      "start": 2236.0,
      "text": "Roman from Electrs recently in Prague, so, had a chance to chat with him a little bit about that, so maybe we need to talk to him about that. But, interesting. And so also, what does this mean then? Let, let's say there's a lot of users out there today who are running, you know, whatever they are, Armbro, Start9, Mineo, Raspiblitz, you know, whatever, one, one of these, is that-- Can they run Frigate on that? And then, I guess the, the Do they need a GPU to really, you know, will, will we need like the umbrels of the world to also come with a GPU for the better experience?"
    },
    {
      "speaker": "craig_raw",
      "time": "37:49",
      "start": 2269.0,
      "text": "So, I mean, no. Like, I, I actually developed, because I wanted to make sure that it worked on normal hard hardware, I've got like a, a fairly low power Intel NUC, box which, has a iGPU, an integrated GPU on it. It's very weak, it's actually weaker than the CPU, but I wanted To make sure that it was still a practical experience. And sure, if I sync my wallet there, I have to wait a few minutes, for it to catch up. but, you know, that thing is probably around six or seven years old now, it's really dated, it's kind of nearing the end of its life, but I wanted to make sure that it was still feasible on that. Now, if you look at the, the box that StarNine currently sells, the Silver One, I believe it's called, that thing has a really powerful i I don't actually know what the numbers are on that, on how fast Frigate can scan, but I suspect it will be pretty, pretty quick. So, you know, hardware is definitely going in the right direction, and obviously the AI story is very much part of that, I think as a developer betting on GPUs becoming more powerful on the hardware in which their software is gonna run is a very safe bet, and that's, again, why I'm seeing all of my software gradually moving towards Using GPUs, so I think it's natural for us as Bitcoin developers to do the same."
    },
    {
      "speaker": "stephan",
      "time": "39:17",
      "start": 2357.0,
      "text": "Gotcha. So you see it like the industry is gonna go this way anyway, and that possibly over time The people, even the people who are selling these boxes, like, let's say, to use our friend Matt Odell's term of the Uncle Jim node, because what he meant there was this idea of not, 'cause sometimes people use that in the sense of custodying funds for your family, but actually, I think what he meant was more like verifying for your friends and family, i.e. running an Electrum server for them so they can point their, let's say, their Sparrow wallet to your Uncle Jim Electrum server. But I guess to, to kind of take that idea what you Eventually what we're gonna see is the \"quote unquote\" uncle gyms are gonna have a GPU powered box that serves as the frigate server for their neighborhood, let's say, something like that. Is that kind of where you see things going? And that means implying that, let's say, the umbrellas and start nines of the world may actually look at starting having GPUs in their future versions?"
    },
    {
      "speaker": "craig_raw",
      "time": "40:12",
      "start": 2412.0,
      "text": "Yeah, look, I, I think that we'll actually just see that as a natural, you know, modern CPUs as the, as the new versions come out. We'll just have good i-i GPUs built into them. Like integrated"
    },
    {
      "speaker": "stephan",
      "time": "40:26",
      "start": 2426.0,
      "text": "GPUs. Yeah, I, I, I don't, I"
    },
    {
      "speaker": "craig_raw",
      "time": "40:28",
      "start": 2428.0,
      "text": "don't think it's necessarily gonna take a, a significant effort from the Bitcoin community to start saying, \"Well, you know, we need to, make sure that the box has some kind of special ho-hardware.\" I think it's just gonna happen any-anyway. I think it's a, it's a, it's a fairly safe, safe bet to say that that's part and parcel of what building a modern hardware platform looks like these days. You know, this, this, as I said, seems like a fairly safe bet to me."
    },
    {
      "speaker": "stephan",
      "time": "40:56",
      "start": 2456.0,
      "text": "One other question around silent payments on, hardware wallets. So can hardware wallets support silent payments right now, or is that a future thing? What's the, what's the status on that?"
    },
    {
      "speaker": "craig_raw",
      "time": "41:06",
      "start": 2466.0,
      "text": "That's a great question. Thank you. yeah, so they can support it absolutely right now. So any QR-based, hardware wallet can, without me releasing another version of Sparrow, Sparrow can build silent payments signing Support in right now. and I think it's, it's actually quite interesting just to dive into that a little bit. So if you think about what silent payments is, you give it a static address, and then it basically calculates the on-chain address based on, off that. So it takes the particular transaction, and it takes the private keys for the inputs to that particular trans-transaction, and it creates the on-chain address based off that. Now, in the case of a hardware wallet, Sparrow doesn't have access to the private- Keys, of course, because the private keys are contained on the hard, hard, hardware wallet. So the hardware wallet actually creates the on-chain address. Now, how does Sparrow know and verify that the on-chain address is correct and it matches up to the one, the actual silent payments a, a, address? Well, it does that via a very clever little approach called a discrete log equality proof. Which allows you to basically say, \"Well, I don't know what the private keys are, but I can see that you used the correct algorithm and you generated the right on-chain address, and that's a cryptographically provable thing.\" So all of that is built into Sparrow today. So the PSBTs have certain fields in them which allow the silent payments stuff to, be able to be carried back and forth and all of that verification to take, take place. So this effort around silent payments isn't just Frigate, it's not just building, you know, the ability into the wallet. There's been a whole lot of standards work which has taken years to reach this point, and now all of that stuff is done. So Sparrow has built on standards. DIP 3 5 4 3 5, sorry, 3 7 4 3 7 5 3 7 6. These are all standards relating to PSPTs and proofs which allow that kind of thing to take place. So as I said, any QR-based hard hardware wallet, whether it's using UIR to scan those QR codes or whether it's using DBQR like the Coldcard does, can, yeah, can, can absolutely today without me doing another thing, can implement Silent payments sending and receiving, and I think that that's quite an important thing, right? So the, the door, the road is open."
    },
    {
      "speaker": "stephan",
      "time": "43:38",
      "start": 2618.0,
      "text": "Sorry, just to be clear, they do, do they support it now, or you're saying they can but they haven't yet?"
    },
    {
      "speaker": "craig_raw",
      "time": "43:44",
      "start": 2624.0,
      "text": "Correct, the second. So they, they can but they haven't yet. So it's, but what I'm, what I'm saying is the, the burden and the onus is on them if they care about privacy, if they want to move the ecosystem forward, the burden and the onus is completely The ones who need to take the step forward. Now, in terms of the USB ones, every USB protocol is different and it's proprietary. So Trezor have their own, Ledger have their own, Jade have their own, everyone's got their own, right? And they're all completely different. There's no standards involved at all. So on that, unfortunately, every single time for the USB ones, I'm gonna have to go in there and adapt it. Now, hopefully that's a fairly easy thing to do, but it'll obviously require their input as well. We have to work- Work together because it's a proprietary pro-prod protocol. But again, all of the QR-based ones, luckily we have standards there, they can implement it today. So I would encourage people if they think that this is important, if they see the value in my argument, to go to their hardware wallet vendors and say, \"Implement this. Why haven't you implemented it yet? because this is an important thing for us to work on.\""
    },
    {
      "speaker": "stephan",
      "time": "44:55",
      "start": 2695.0,
      "text": "Gotcha. And so off the top of my head, then the QR supporting ones, obviously Coldcard Q, Block Silent Payments, I guess Foundation Passport, Specter DIY, Seed Signer, I guess those are the main ones I can think of at the top of my head, in terms of, oh, and maybe that Crooks one, I don't know. And then on the USB side of things I guess, is that where like HWI and things like that are also related, but you still have to go and do extra work to make it work with Sparrow? And then I guess that's the other thing, other wallets who wanna support silent payments, do they then also have to go and do that work, or can it be standardized there?"
    },
    {
      "speaker": "craig_raw",
      "time": "45:32",
      "start": 2732.0,
      "text": "Yeah, so I think, you know, I, I don't really see any new hardware wallets coming to market now which invent their own new USB protocol. I think, I think everyone's kind of realized that that was the old way of doing things The majority of hardware wallets, in terms of Ledger, Trezor still use that approach, but new hardware wallets don't, right? You don't see new hardware wallets coming to market and saying, \"You know, I'm gonna use USB,\" it's just not the, for whatever reason, it's just not the way that things are going, So all of the new hardware wallets generally have QR support, I think it's become obviously the most simple and, User-friendly way for us to send information back and forth in an air-gapped manner. and as I said, that approach is already got standards connected to it, and there's no, there's no barrier in terms of those vendors coming forward and saying, \"We have implemented silent payments, receiving and sending in our wallet.\""
    },
    {
      "speaker": "stephan",
      "time": "46:35",
      "start": 2795.0,
      "text": "Interesting. So, yeah, so I guess summarizing a few of these things, as you're saying, there's w- you know, there's a lot of work been done in the standards to try to make these things compatible, but they're still- I guess some work to be, to be done in terms of getting people to use things like Frigate or to build that into, let's say, Fulcrum and Electrs and whatever else, and then I guess maybe there's a bit of an advocacy side of it of people trying to push Binance and Trust Wallet and Coinbase and whoever else has a big wallet to implement silent payments, and obviously that can be sold both on the privacy, see, benefit and also the UX benefit to say, hey, your users should have a contact list and they should just send like that, So i-is that, the kind of, is that where we are, is that where we're at, or anything else you wanna add on the silent payment side?"
    },
    {
      "speaker": "craig_raw",
      "time": "47:23",
      "start": 2843.0,
      "text": "Yeah, no, I think that's, that's good. I think, you know, in terms of adoption, it will need to start within the Bitcoin community. People are gonna have to say, you know, are we satisfied with seventy percent address reuse and climbing? Is that a situation that we are comfortable with? And if not, what are we gonna do, do about it? And if we're gonna do something about it, I think that that's a question every Bitcoiner should be asking themselves, because if you're not, I think you are welcoming the world of a single address per- Person, I think that's, that's the world that awaits you, as you got on-chain address per person. but yes. Reminds"
    },
    {
      "speaker": "stephan",
      "time": "48:04",
      "start": 2884.0,
      "text": "me of something I heard, Carl from Money Badger tell me that's like sometimes regulators will regulate things as they are used, right? Which, lines up with what you were saying, Craig, because, you know, I think that in, in that context, he was arguing about medium of exchange and how people, Bitcoin doesn't need to be seen as only store of value, that it should be allowed as a medium of exchange And lawmakers will, try to put the ban hammer down on people using different addresses or that's seen as like a, you know, shady or evil or whatever dodgy privacy practice instead of, just good hygiene."
    },
    {
      "speaker": "craig_raw",
      "time": "48:42",
      "start": 2922.0,
      "text": "Yeah, yeah, I, I couldn't have put it better. you know, They will regulate things as they are used and not in the way in which you want to use, use them. And sure, you might say, \"Well, doesn't apply, apply to me, I'll just keep on doing the way that I do.\" But, I think that that's a very short-sighted and myopic way of seeing the, the world, the reality is, your anonymity set is dependent on others, and you can't escape that fact. You can't escape the fact that if address reuse just gets more and more and more, your anonymity set shrinks and shrinks and shrinks, and that's a fact. It's an undeniable, undeniable fact. So, you know, all of those, people who like to say, you know, how the masses use the This doesn't affect me, I think they are burying their heads in the sand."
    },
    {
      "speaker": "stephan",
      "time": "49:31",
      "start": 2971.0,
      "text": "Okay, so yeah, so we'll leave that there on the silent payment side of things. Let's flip now to multisig UX in twenty twenty-six. So obviously, you're the maker of Sparrow Wallet, you're one of the well-known, you know, guys out there and wallets out there that support people who wanna do their own multisig. can you comment a little bit on, you know, where you see Bitcoin multisig UX these days? Like, what is the UX at? what And, yeah, just any general comments there?"
    },
    {
      "speaker": "craig_raw",
      "time": "50:00",
      "start": 3000.0,
      "text": "Yeah, I think, you know, multisig is fairly mature now. I think we, we have, effectively, reached a point. well, yeah, it's, it's, it's hard to say whether things are gonna move forward to a different standard at this point because the actual standards around things like frost, have been very slow to emerge. so I am personally as a sparrow- I want a developer not pushing forward on that, it's not my particular field to do so, you know, there are others who are more deeply involved, but what I haven't seen for whatever reason is standards emerge on, on that for us wallet developers to use. So we are on, Pay to Witness script, script hash, the kind of, normal, traditional, if I can use that word, way of doing multi-sig, and that seems to be the default. it obviously has some downsides. It's, you do reveal your two of three or three of five or whatever whenever you pay, so it's not ideal, but, and it's, you know, doesn't have some of the fancy things like key rotation that Frost promises to have. But as I say, that is what People use and, the standards for anything else have been very slow to emerge."
    },
    {
      "speaker": "stephan",
      "time": "51:23",
      "start": 3083.0,
      "text": "And that's just what works today, and that's what's practical for a lot of multisig, at least when we're talking about self-custody for larger amounts, that's, you know, what a lot of people are doing. any comment on the miniscript stuff, like the whole inheritance, the time-locking, vaults? do you have any thought on that and whether that would be relevant for you on a sparrow, in a sparrow context?"
    },
    {
      "speaker": "craig_raw",
      "time": "51:45",
      "start": 3105.0,
      "text": "So I, I think When people use the term manuscript, what they generally are referring to is something we call a decaying multisig, which is a funny term, but it does, does describe what it is, right? So you start off with, say, a three-of-five, and then it decays to a two-of-three, and then it decays to something like a one-of-two. That's kind of what they're saying, now the reality of the implementation of that means that you have to rotate your core Into new UTXOs, otherwise they decay to a lower level of protection. That's what that scheme is kind of saying, right? And it, it's, it's a, it, it must be a proactive thing. So you have a certain time period, which can be, a relative time period or an absolute time period depending on the locking script that you use, and then you have this idea that every so often you have to rotate those UTXOs. Now, unfortunately, that ha- has a number of different implications. It has implications around privacy because the majority of people, and again, I'm a pragmatic developer, I look at what the majority of people are gonna do, they're going to say, \"Well, I've got a bunch of UTXOs that I have sent into or received on this multisig, wallet, and I'm now...\" I have to rotate them, so I'm gonna go ahead and rotate, rotate them, and I'll generally do them all at once. And unfortunately, that creates this on-chain signature which moves everything across at once. Now, of course, you don't have to do that, but I suspect that's what the majority of people are going to do."
    },
    {
      "speaker": "stephan",
      "time": "53:23",
      "start": 3203.0,
      "text": "The people would do, because they'll see it as like, oh, eleven months or twelve months, okay, I better do my refresh, and then at that point, they're gonna consolidate all their UTXOs. And so I guess your concern then is"
    },
    {
      "speaker": "craig_raw",
      "time": "53:39",
      "start": 3219.0,
      "text": "Even if they take the effort to send them one by one, they're probably all gonna appear in the next block or the next two, two blocks, and after you've done that a few years, it's obvious on chain, right? You just see, well, this is interesting, every eleven to twelve months, this block of UTXOs jumps across from one, you know, address to the next, and that, that I think is an on-chain thing that will get analyzed in future. so, you know, we need more tools, so we, we, we need some idea Broadcast with delays, so people can hit the broadcast button, but the actual transaction only gets sent later on, right? And that's, that's one of those things which we just don't really have yet because it requires a server. So I put a PR into Bitcoin Core which has this idea of broadcast pool, which is sort of a pool that sits there, of your broadcasted- To your node, but not yet broadcast to the network transac-tions. But that's not a thing yet, right? It's, it's, I think it's gradually being worked on in ways and means, but it's not yet there. So Until it is, I think we have a lot of issues around from the privacy angle of this decaying multisig idea. Now there's also other issues, right? I think just the idea of having to refresh every so often is quite a challenge in itself, particularly when you have a geographically distributed multisig, which is obviously the type that we all recommend people have. You now have to go and visit all of your locations, which is actually a good and healthy thing to do, but I suspect The people just won't do it, and as a result, they will end up with a decayed multisig which has less security than they intended it to. And, you know, that's a, that's a concern to me anyway. I just worry that that's not ideal for the self-sovereign user. Now, where I do think decaying multisig has a lot of value is in a managed solution, and you see a lot of these, wallet developers coming out with managed solutions like Nunchuck or Or, AnchorWatch, you know, they, they, they present a, a sort of nano solution and they help you through this process, and I think that that makes a great deal of sense. But that's not the market that Sparrow talks to. Sparrow is very much about the self-sovereign user, Have no i, no desire to create a managed service. So I need to consider what is best for Sparrow, and at this point, I'm not confident that the Decaying Multi-Sig is the ideal solution for Sparrow users."
    },
    {
      "speaker": "stephan",
      "time": "56:13",
      "start": 3373.0,
      "text": "Interesting. Okay. And then the inheritance case where maybe, as I understand, you can have like the main spending path could be whatever, let's say it's your two of three or your three of five, and then an inheritance case could be different keys to those, but for your son or your daughter or whatever. for them to recover. So what do you make of that? Like, are you just saying that's in a similar category to the decaying multisig for you?"
    },
    {
      "speaker": "craig_raw",
      "time": "56:36",
      "start": 3396.0,
      "text": "Well, it is. I mean, there's, there's, there's no other way to implement it, right? From a practical Bitcoin script point of view, you, you have to implement it in the same way. You don't have a choice. I wish we had better tools. I, I wish that we had the kind of vault tools that would require soft vaults for Correct. Yeah, yeah. So, you know, I, I would very much welcome those. I think that, inheritance is a major issue, and we really do need a better solution for it. so I'm, I'm very cogn-cognizant of that. I'm just concerned that the downsides at this time outweigh the upsides."
    },
    {
      "speaker": "stephan",
      "time": "57:13",
      "start": 3433.0,
      "text": "For you, it's not worth it. Okay. And then, I know there's another kind, which is like an expanding multisig, so that's like the opposite. So I think the-- So I was, I was talking with from Liana Wallet or Wizard Sardine, and his explanation was more like, let's say you've got a business and, you know, you're a co- you have a co-founder, you and the co-founder have, you know, a two of two in the standard pathway, but then you could have, in the expanding case, let's say after six months, a board member, so it's like any two of three Either the-- if you and the co-founder have a disagreement, then it's one of the co-founders and the board member separate who can also sign. Any thoughts on that expanding multisig idea or maybe just not as interesting for you, the, the business use case, let's say?"
    },
    {
      "speaker": "craig_raw",
      "time": "57:57",
      "start": 3477.0,
      "text": "Yeah, look, I, I think that they're certainly valid to that. I mean, I think from a security point of view, you could, you could say, well, you know, you, you basically, you, you're either increasing or decreasing the, the, the, the, the, And ultimately,"
    },
    {
      "speaker": "stephan",
      "time": "58:13",
      "start": 3493.0,
      "text": "it,"
    },
    {
      "speaker": "craig_raw",
      "time": "58:14",
      "start": 3494.0,
      "text": "it boils down to people, right? You can't get away from that fact. We talk about tech, but ult-ultimately, we're talking about, do I trust this person or not, right, to actually sign? Yeah. now that level of trust determines whether you are increasing the security or decrease- decreasing it, but the fact remains is that the mechanism remains the same, right? The same Bitcoin script mechanism is there, which means the rotation need is still there. So all of the concerns that I just mentioned still apply. It doesn't- really matter, how you, you consider the people involved, the, the tech remains the same."
    },
    {
      "speaker": "stephan",
      "time": "58:49",
      "start": 3529.0,
      "text": "When it comes to multisig steps, and one step is registering the multisig quorum on the device. Now My understanding is that most hardware wallets do, you know, or a lot of them can do this, but I know, for example, Trezor is one example where I've heard they don't have that yet. I'm curious if you have any comments on that, like, is that- Something, you know, y-y-you have noticed in your work on this."
    },
    {
      "speaker": "craig_raw",
      "time": "59:15",
      "start": 3555.0,
      "text": "Yeah. So look, it's obviously better for the, the full description of the multisig wallet to be registered on the device, because then the device can verify that some of, for, for ex-example, it can verify the change amount, right? It can say, \"Well, this is actually change,\" and it can do that independently of the sort of coordinator. So it's clearly a, a better system. Unfortunately, many of the hardware, or some of the hardware wallets just don't have the capability to store that information, and that's why you don't see it on certain device buses. But, from the point of view of a multisig user, I think you should always consider that a strong factor in, in your choice if you are using multisig, definitely prefer the devices that can do that versus the ones that can't."
    },
    {
      "speaker": "stephan",
      "time": "01:00:06",
      "start": 3606.0,
      "text": "Gotcha. So what, i-in your experience, which are the ones that can- Register the quorum."
    },
    {
      "speaker": "craig_raw",
      "time": "01:00:12",
      "start": 3612.0,
      "text": "So pretty much all of them, I think, except for the Trezor, I think that's, that's the, the only one which, which doesn't really have that kind of built into it. I suspect they're gonna add it, just because it's become kind of the default now. it's, it's, it's not a huge amount of data to be able to store, but, you know, they have-- They, they were one of the sort of early guys, to give them fair, fair dues, Products which, you know, some of them just don't have it, they just don't have the, the physical capability to be able to do it. So I think, I think that that kind of- It's like"
    },
    {
      "speaker": "stephan",
      "time": "01:00:48",
      "start": 3648.0,
      "text": "a legacy problem because some of the early devices, that kind of thing. But I guess they could just sort of say, \"Look, get out, you know, it's in our new device, so buy the new one, \" that kind of thing. So, do you have any other thoughts around, mixed vendor multisig setups? Any combinations that you would recommend"
    },
    {
      "speaker": "craig_raw",
      "time": "01:01:10",
      "start": 3670.0,
      "text": "Not to, you know, be prescriptive here, you know, I think Sparrow needs to be sort of neutral and that- You see yourself"
    },
    {
      "speaker": "stephan",
      "time": "01:01:18",
      "start": 3678.0,
      "text": "as a neutral tool, yeah. Per se, and that people need to just be able to use whatever. But obviously, they, like we said, they need to think about some of these issues like the quorum, the registering step. And I guess just for listeners, if you're listening and you're like, \"Oh, what, what are they talking about?\" I'll just very quickly. So, sorry, just So the normal story with a hardware wallet is that it may have, you know, like a master xpub and your private keys and so on, and it can sign just, you know, one, one of one. But in a multi-sig context, what you're doing is actually sharing kind of the public keys of all the other devices inside that quorum, like the three of five or the two of three or the whatever you're using, and then this register the quorum step, which is part of the multi-sig setup step, is so that the device, as Craig was mentioning, knows which It controls or it's, it knows that it is part of that set, and then also to Craig's point, that it can check the change address is also its own address, because it, or it's in, included, it's included in that, as opposed to, let's say, some of the hacks that were out there where maybe it would send the change to a hacker, right? Like that kind of thing. So it's a, it's a security thing and a safety point that helps, us, I guess, keep our keys secure in the multisig context. So Sometimes we get into technical things, and I, I, I remember when I ch- when I chat to people in person, they're like, \"Oh, sometimes it's a bit technical, you know?\" now, on the question of output descriptors and backups and things like this, do you have any thoughts on this, on like where we, where we should keep that, how people are managing and securing those for the long term?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:03:02",
      "start": 3782.0,
      "text": "Yeah, I mean, I, I think, you know, the, t- there's two kind of ways that I have personally said So multi-sig users should, think, think, think about that. The one is just to create, in, in the Sparrow sense anyway, a, a backup of your Sparrow wallet file, which will obviously have all of that information in it, and the second is to, create a backup of the output, the script, the script that describes that multi-sig wallet. Now, why is this important? it's important, and I think most multi-sig users know this by now because it has been widely talked about, but you need to have a record Of all of the private keys in order to create a spending transaction on that multisig."
    },
    {
      "speaker": "stephan",
      "time": "01:03:47",
      "start": 3827.0,
      "text": "Sorry,"
    },
    {
      "speaker": "craig_raw",
      "time": "01:03:47",
      "start": 3827.0,
      "text": "correct, Stephane, Stephane. Thank, thank you for making that clear. Yeah. So if, even if you have two of, two of three, you may, you, you, you need only two of the private keys, but you need all three of the public keys, and that's the one kind of little gotcha that multisig has always, always had. That sometimes"
    },
    {
      "speaker": "stephan",
      "time": "01:04:03",
      "start": 3843.0,
      "text": "people have kind of forgotten or not, maybe not aware, but yeah, okay. so yeah, so we'll The other one I wanted to ask you about is the, the one about the transaction descriptions and things. I know you had, I think you had a bit for that, can you just explain a bit on that?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:04:19",
      "start": 3859.0,
      "text": "So I, I think you're actually referring to the, the, the wallet labels."
    },
    {
      "speaker": "stephan",
      "time": "01:04:23",
      "start": 3863.0,
      "text": "Yes, sorry, wallet labels. Yeah,"
    },
    {
      "speaker": "craig_raw",
      "time": "01:04:24",
      "start": 3864.0,
      "text": "so that's the three to nine, so basically when people are sending amounts out, right? In terms of, of privacy, you generally, want to be somewhat aware of what UTXOs are going, going where. Now this very- Various ways to manage this, you can say, \"I'm gonna create a new account in my wallet, and I'm just simply gonna say all of these UTXOs are kind of the same on a privacy level, they're all kinda linked on that level, and that's fine.\" A different way of doing that is to say, \"I'm gonna have my wallet, and I'm gonna label every transaction that goes out, and, and then I'm gonna say, when I send an amount, I'm, I'm gonna look at the labels, and I'm gonna say, \"Well, I understand Change from this transaction in a new one, right? Because people can then, if they have all the information about me and they can see how things and they've worked it out, they can then see this link on chain. So the labels are a way for you to be able to manage that particular issue, right? To be able to say, \"Right, I had change from this transaction, I'm not gonna use change in this new one, and I'm gonna see that because of the label that was applied.\" What the Bib says is, here's a way for you to be able to, in a standardized format, export all the labels from my wallet and import them else, else, elsewhere. So this, this useful meta information which isn't on chain can therefore be transferred between one wallet and the other, can be transferred into backup. You know, it's, it's kind of a generally useful thing. And that's what this wallet labels Bib does, is it basically creates this standardized format that allows WALLETs to be able to import and sort of export, and this has been very well received by the Bitcoin community, and now you have many wallets which have built, the ability to import and export wallet labels in this way."
    },
    {
      "speaker": "stephan",
      "time": "01:06:22",
      "start": 3982.0,
      "text": "Now, let's talk a little bit more, just I guess zooming out a little bit, talking about Bitcoin adoption generally and regulation and some of these things. I think we're seeing a bit of a divide now in, in some sense, like you can see, let's say, the purists on one sense who are Let's say more focused on self custody and peer to peer and de-decentralized and permissionless, and maybe on the other side, let's say the, the pragmatists in, in the adoption sense, they might be more kind of okay with the idea of corporate adoption, ETFs, treasury companies, this kind of thing, tradfi, let's say, bridges. do you think that- Is it gonna help or harm overall in terms of, you know, bringing people in? But on the, on the downside, is that kind of diluting the ethos or diluting the, you know, the decentralization components of Bitcoin?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:07:12",
      "start": 4032.0,
      "text": "Look, I, I think as, as we've been talking throughout, I think the, the common thread here is that one has to be pragmatic about things. the reality is that these things are going to happen anyway. what we have to do is try and create the best solution solutions that we can to have the future that we want to see, and we have to, when, you know, something comes along which is obviously counter to that, we have to at least warn people about it. We can't necessarily change the fact, by control, but we can at least speak out, and say, \"Well, be aware that if you're going down this road, these are the potential consequences.\" But what I actually prefer, rather than warning people, which is Not that effective at all, it's just simply provide a more effective tool that does whatever this thing is in a way that people actually prefer, and that's where I typically put my time. So I, I actually don't really talk much, in so-terms of an online sense, I'm not sort of very active on X or anything, I prefer to let the code talk, form for me, so I prefer to rather work on things which people can, can, can use, which, Provide a step forward. So I think Silent Payments is a great, great examp-sam-sam-sample of that, hopefully just a more usable way to interact with Bitcoin that is more private, kind of under the hood. that's more or less how I think about it. you know, it's, it's, we can get into specifics around certain, aspects of it, but that's my kind of core, core ethos."
    },
    {
      "speaker": "stephan",
      "time": "01:08:55",
      "start": 4135.0,
      "text": "We are seeing, you know, different- Regulatory or tax or, law moves, some of them are against Bitcoin, some of them are bad. Obviously, in South Africa, there is a big one right now that, you know, I did an episode recently, listeners, check it out with Ricky, talking about that. Now, Craig, I'm not expecting you to be like a legal expert on the technicalities of that specific thing, but just broadly, what do we do about this question of, let's say, bad regulation or bad laws or potential bans? In this case, it's a potential- Effective banning of self-custody in, you know, for Bitcoin in South Africa. So what's to be done there?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:09:35",
      "start": 4175.0,
      "text": "Yeah, so I mean, that's, that's, as you say, Stefan, not really my, my, my field, but, you know, if you're in the field of law, you have to counter law with law. you have to look at, are these regulations-- and I wanna be clear on that word, they're regulations and not laws, are they, are they actually legal? you know, a government body can Put a regulation forward, that doesn't mean that the regulation is legal, in the case of the South African draft regula-late-late-late-lation, there's a lot to suggest that it is not legal in terms of the constitution of what South Africa is. It has a recent and forward-thinking constitut-constitution, which was drafted at the time of the transition from the apartheid government into the democratic government, and That's, that's a very good, good thing because it was, it was well written and it contains provisions around privacy, it contains provisions around, private pro-pro-property, and I think that we need to, fall back on those now. Now, obviously that's not my, my job, I'm not a lawyer, But, you know, it's going to take time, and I think that, you know, we have to be patient and we have to look at kind of the long frame here and I don't think we should necessarily view people as enemies. I think people have, both inside government and without, some, some of them certainly aren't good actors, but, you know, I think we should take the default of saying, you know, some of these regula- like, like, like nations may have been drafted with, certain thinking in mind, that they may not have taken the full legal landscape into account, and let's help those people understand what the full legal- Landscape is in order to, come to a, a, a solution which is actually legal within the laws of that land. as I said, luckily we have a long history, throughout the world of people fighting for freedom, and we have many wars in our past which have, had people, you know, giving their lives for those freedoms, and we need to make use of those, we need to defend those. that's how I see it. it's, it's not an easy solution, it's not a quick solution, but I think it's the only solution that will have lasting impact."
    },
    {
      "speaker": "stephan",
      "time": "01:12:04",
      "start": 4324.0,
      "text": "And maybe your answer on this question will be the same, but do you worry that governments will target what they could view as a privacy feature like silent payments?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:12:13",
      "start": 4333.0,
      "text": "Well, it's, it's, it's just very, very hard to do so, right? It's, it's really like, one of the most, you know, it's, it's-- that's actually one of the reasons why it is such a interesting technology to work on. So if you look at coinjoints, we obviously have the Sum, Samurai, Samurai case there as a prime example of the fragility of that particular approach. I wish, I wish that wasn't the case. I, I certainly hope that they, that there's a, a There, but, the reality is different today and, right now, we have, an issue with coinjoins worldwide, that's just the truth of it. With silent payments, we have no one running, you know, some kind of server which different parties have to connect to create a combined trans-transaction. Silent payments is a different kind of thing altogether. But it is nevertheless a very important privacy improvement which doesn't carry that sort of legal risk because it's simply using a cryptographic algorithm. it doesn't have-- there is no server involved, there's no kind of central server involved, so that particular risk or that particular vulnerability just--"
    },
    {
      "speaker": "stephan",
      "time": "01:13:31",
      "start": 4411.0,
      "text": "There's"
    },
    {
      "speaker": "craig_raw",
      "time": "01:13:32",
      "start": 4412.0,
      "text": "less of"
    },
    {
      "speaker": "stephan",
      "time": "01:13:32",
      "start": 4412.0,
      "text": "that"
    },
    {
      "speaker": "craig_raw",
      "time": "01:13:32",
      "start": 4412.0,
      "text": "risk. Just doesn't exist."
    },
    {
      "speaker": "stephan",
      "time": "01:13:34",
      "start": 4414.0,
      "text": "As a solo dev, how do you think about the sustainability of building Sparrow long term?"
    },
    {
      "speaker": "craig_raw",
      "time": "01:13:39",
      "start": 4419.0,
      "text": "Great question. yeah, I mean, you know, in terms of, I think Sparrow's arc, I think a lot of people actually don't really upgrade all that often. I wish they did, but they actually don't. they, they sort of say, \"Well, this is, my tech stack and it's working for me, and I don't wanna touch anything.\" And I can kind of see that point of view. Obviously, I wish that they didn't upgrade, otherwise, what's the point of me doing anything? Is that, you know, Sparrow is gonna keep going, going forward even if people aren't quite happy to kind of leave it where, where it is. I think silent payments for me was, Personally, a major step forward in terms of adding something new to the ecosystem rather than building on the standards of others. you know, I was personally involved in many of the standards around silent payments and wallets, and I think the work on Frigate is genuinely novel and adds something new to the world. So for me, that's satisfied a long term itch of actually contributing beyond providing a good product, just actually building some-something which I think has real material value and kind of moves us forward. but, you know, I don't intend to personally be on the cutting edge of, say, things like FrosteNet. I just, I think that's someone else's work. Happy to look at it once standards emerge, but, you know, that's not personally what I'm going to do. So, from a long-term sustainability point of, point of, point of view, I think Sparrow is in a good place. I think I've spent a lot of years, working on things under the hood that people aren't ever aware of, kind of making sure that, dependency management, that, provenance, all of these kind of things are really well handled, and I'll keep working on that. On, on that, but I don't, I, I don't kind of see dramatic, radical change, in Sparrow. I don't think that's what people want. I think they want a stable tool that works much in the way it does today, and that's what I'm gonna focus on, and I think that, that will give me the ability to keep on doing it. Beyond that, it's hard to say, we'll have to see. at some point, obviously, we'll have to consider, you know, others, but,"
    },
    {
      "speaker": "stephan",
      "time": "01:16:08",
      "start": 4568.0,
      "text": "Fantastic. Well, look, I think we've got to leave it there, but, you know, I think the community is really appreciating all the work you're doing on Sparrow. It's a great tool, so many people use it, certainly the people who really prioritize the financial sovereignty aspects of it and, the privacy elements of it, and, yeah, we'll leave it there. So listeners, go and check it out, sparrowwallet dot com. Make sure you share this episode so more people can hear, some insight from Craig. And Craig, thank you for joining me today. Awesome,"
    },
    {
      "speaker": "craig_raw",
      "time": "01:16:38",
      "start": 4598.0,
      "text": "Stephane. Thanks for having me."
    }
  ]
}
