{
  "episodeId": "SLP766",
  "speakers": {
    "stephan": {
      "name": "Stephan Livera",
      "role": "host",
      "tag": "STEPHAN"
    },
    "keith_mukai": {
      "name": "Keith Mukai",
      "role": "guest",
      "tag": "KEITH"
    }
  },
  "segments": [
    {
      "speaker": "stephan",
      "time": "00:00",
      "start": 0.0,
      "text": "Hi everyone, welcome back to Stephan Livera Podcast. Today we're gonna be chatting about dice rolling, entropy, and the SeedSigner, and joining me today is Keith Mukai as, lead developer of SeedSigner. Welcome to the show, Keith."
    },
    {
      "speaker": "keith_mukai",
      "time": "00:12",
      "start": 12.0,
      "text": "Hey, thanks for having me."
    },
    {
      "speaker": "stephan",
      "time": "00:14",
      "start": 14.0,
      "text": "So Keith, I saw you had, some recent, research or findings that you put out on dice rolling because you were trying to, let's say, correct some misconceptions around that. So, you know, why don't you, start us off there? What, what was the, what were some of the key learnings from that?"
    },
    {
      "speaker": "keith_mukai",
      "time": "00:30",
      "start": 30.0,
      "text": "Yeah, so, I mean, in, you know, in the wake of the Coldcard exploit, right? Like everyone is understandably terrified about entropy, like, and what this whole episode revealed was just so many people just don't even understand any of it, right? So obviously there, there were the people that got horribly wrecked by trusting the, the on-board, RNG code on the Coldcard. But even the people that did the dice rolls and they were safe, once the exploit was like fully explained, even days later, people are like, \"I did the dice rolls, am I okay?\" Like Like, come on, you know, the explanation is out there, right? The, the exploit has been described, and people just still didn't have any, Core understanding of what the dice rolls provided them, whereas like if they really understood, and I, I don't want this to sound like insulting or condescending, like I totally understand, like the, the terror, the panic, the, the confusion of, of that time, but like If you can understand the core principles behind dice rolls, then you can sleep easy, you know, through this. So I just wanted to- At least explain, you know, what, what the dice rolls are, how it works, you know, what, what, what, what the basic principles are. but then of course, anytime you talk about dice rolls, then all of the folklore, all of the superstition comes out. You have to use casino-grade dice. You've gotta fill a, a, a cup of water with salt and then float your dice and, you know, poke at them and make sure that, you know, a different face, you know, pops up each time. you know, If you had to do a hundred and fifty, and of course, the truth"
    },
    {
      "speaker": "stephan",
      "time": "02:24",
      "start": 144.0,
      "text": "isn't that, right? So no, no, so it's,"
    },
    {
      "speaker": "keith_mukai",
      "time": "02:29",
      "start": 149.0,
      "text": "so now I, I, in the, in the write-up that I, I published, I, I listed all of my sources and methods, and so the idea is that if I got anything wrong, like you can see exactly like what I was pointing to and, and you can correct me or you can find better research. and I used Claude, alright? So As far as I know, Claude didn't hallucinate any of these findings, but double-check, double-check the work, right? So the two biggest studies that we could find in terms of dice roll fairness, like how bad is a cheap pair of board game dice? both studies were kind of shocking. They only found a one point four percent variance from fair, and, and that's with like the cheapest dice that they tested, and this is over like hundreds of thousands of test rolls. I was expecting worse numbers than that. And they verified that casino-grade dice really are as fair as they purport to be, like within the range of, you know, accuracy of their measurements. But so if, like, if you open your Monopoly game and take dice out of that, and they're Accurate to within one point four percent, you know, when I, when I had Claude run the numbers and the simulations for a twelve word seed, you're expecting one hundred and twenty eight bits of entropy from your dice rolls. And even if we inflate the inaccuracy, and let's say your dice are two percent inaccurate, you know, doesn't sound like much, but it's way more than one point four percent. Then in your, over your 128 bits, you lose 0.2 of a bit, and that's if you're only rolling with one die, that is 2% unfair. So, Like, yeah, if it makes you feel better, you can buy casino-grade dice, but I just kinda wanna stop people from saying like, \"You're screwed unless you do this,\" right? It's not necessary. Like You know, I was, I was looking at Amazon, like, there's some really cool looking casino grade dice, you know, I want, I want an orange transparent set of casino grade dice. Right, just for"
    },
    {
      "speaker": "stephan",
      "time": "04:51",
      "start": 291.0,
      "text": "fun, right? Yeah, exactly."
    },
    {
      "speaker": "keith_mukai",
      "time": "04:53",
      "start": 293.0,
      "text": "Cool, go ahead. It's thirteen bucks, you know, it's fine, you know, whatever. Like, your, your whole like seed rolling ceremony should have like a sense of like fun and coolness and, you know, prestige about it. No problem. But just like, don't scare people unnecessarily. Don't let it stop you from,"
    },
    {
      "speaker": "stephan",
      "time": "05:09",
      "start": 309.0,
      "text": "yeah, yeah, it's an interesting point, it's a good point. and so as you said, like kind of the, the rule of thumb is sort of fifty rolls for a one hundred and twenty-eight bit, for twelve words, and then if you're doing a twenty-four word seed, then that's where ninety-nine rolls is typically the, the rule of thumb. and then, so I guess the key points really are Even if you use cheap dice, that's okay, it doesn't have to be a casino roll, a casino, you know, level. and basically fifty rolls and ninety-nine rolls are typically the, the rule of thumb that people go for there. and then you also mentioned, in terms of like how to, the tech, the dice rolling technique. So what are your tips on dice rolling technique?"
    },
    {
      "speaker": "keith_mukai",
      "time": "05:46",
      "start": 346.0,
      "text": "Yeah, so that was like, that was the one thing that research said does actually matter. And, I mean, the research is ridiculous. Like, they start off by, you and just like dropping it, like so you're not even like throwing it, right? And like, oh yeah, guess what? That, that yields pretty unfair rolls if you use a crappy technique. And then, you know, it's like, okay, if it, if you roll it, but it only bounces, you know, two or three times, that's not as good as four or five bounces. And like, okay, like none of this is surprising. Like, we all have an intuitive sense of how things tumble chaotically in the world. And if you're doing and so the, the, the, the best solution is, you know, raid all of your board games or, or buy some extra dice, throw them all in a box, like if you have, you know, ten dice in a box and you just shake up the box, turn it over, and then just read off the rolls, you know, kind of in whatever order they land in. Like, first of all, shaking up, shaking them in a box is gonna be so chaotic, like it's gonna be an ideal- Mixing. And then you're doing multiple at a time, so it goes quicker. And any flaws that are in any one die, it's just gonna be averaged out across the collection. And even more so if there, if there's variation, like different types of dice, you know, in your collection, like, \"Oh, these two were from Monopoly, this one was from, you know, whatever game. These, these four I bought online yesterday.\" just So if you really wanna be paranoid, just get a variety of different dice, throw 'em in a box, shake it up, and it's, it's, it's easy. Like, we don't have to make these things complicated, you know? You don't have to like, you don't have to like, say a, a twenty minute mantra, you know, to get in tune with the universe before you do your dice rolls. Like,"
    },
    {
      "speaker": "stephan",
      "time": "07:44",
      "start": 464.0,
      "text": "the, the, the chaos, entropy gods, here upon us. Yeah. Yeah. so let's talk about the other Interesting as well, which is verifying our entropy, right? Because as part of your write-up, you also expelled out how some of the different hardware wallet, you know, manufacturers, projects, they might have a different technique or method of actually incorporating that entropy. So spell that out and what are the steps you would recommend to verify that entropy?"
    },
    {
      "speaker": "keith_mukai",
      "time": "08:15",
      "start": 495.0,
      "text": "Yeah, so this was the most disheartening part of the research. from my like, part of the echo chamber of like the Coldcard SeedSigner world. Coldcard and SeedSigner use the exact same approach to dice rolls, so if you enter the same rolls into both devices, you'll get the same final result. So that, that is a huge principle for verifying, right? So if, if my implementation in SeedSigner is buggy or malicious, you'll get a different answer than in some other tool that isn't malicious, you know, unless- Me and every other tool are, you know, in somehow colluding, right? But they can, yeah. you know, once, once you've verified in two or three other places, like it's getting pretty thin, you know, odds that, that there's any, anything fishy going on. But what was disheartening was, outside of the SeedSigner, Coldcard, Krux world, is that there are different ways to process these dice rolls, and so there really isn't any one standard. And but they roughly break down into either you enter each dice roll into the device itself, and then the device is gonna do some, you know, processing on, on the roll sequence. or like, BitBox, I guess they, they don't like the idea of doing, the roles on the device, but they give you a worksheet, and so you can still do dice rolls, but you just follow their worksheet like by hand with, you know, pen and paper, and then the end result is your mnemonic phrase, and then you just need the device to do the, the final word calculation, which all the devices support anyway, but- So the big difference being, if you're using a worksheet for your dice, it's conceptually the same as just picking fifty-nine words out of a, out of a hat. Yeah, right. Like Michael"
    },
    {
      "speaker": "stephan",
      "time": "10:18",
      "start": 618.0,
      "text": "Flaxman said back in the day, seven years ago or whatever, right? Yeah,"
    },
    {
      "speaker": "keith_mukai",
      "time": "10:21",
      "start": 621.0,
      "text": "yeah. Yeah, yeah. And it was, it was disheartening when I did this research because, you know, there's no BIP to like codify like the way to do dice rolls. And like, again, with all the confusion and panic, you know, the last couple weeks, it would be reassuring if all of the devices were all uniform and had the same implementations that we could cross-verify. Right, methods of doing"
    },
    {
      "speaker": "stephan",
      "time": "10:46",
      "start": 646.0,
      "text": "that. Yeah. And then, I guess you also had an interesting point around verify, around how the user can verify, which is like with a fake- You know, test seed, right? Again, listeners, never, ever type your seed into an online connected device. But you, you had an interesting method. Can you spell that out for us?"
    },
    {
      "speaker": "keith_mukai",
      "time": "11:02",
      "start": 662.0,
      "text": "Yeah, so there are different websites that, you know, again, as you said, never enter your real dice rolls or mnemonic into, but there are websites where you can enter your dice roll sequence and get the same result that Coldcard and SeedSigner and Keystone and a couple options, will yield. And obviously that's not secure for your real seed, but the whole exercise is just to prove that SeedSigner isn't doing anything buggy or malicious, that our implementation matches everyone else's. And so you're just verifying on a set of test rolls, and when I say test rolls, it shouldn't be, you know, one, one, one, one, one, one, one, one, one, right? Like, do your real whole roll process. Enter those rolls into multiple devices or even websites, verify that they all give you the same answer, and then throw those rolls away, like consider them compromised. Right. It's like a"
    },
    {
      "speaker": "stephan",
      "time": "12:00",
      "start": 720.0,
      "text": "throwaway seed, right? The idea is it's not your real seed, you're doing a throwaway just for the sake of verifying that the dice roll process was done correctly, and then you can go and do the real one for real, not typing anything into an online computer, et cetera."
    },
    {
      "speaker": "keith_mukai",
      "time": "12:13",
      "start": 733.0,
      "text": "Yeah, and even the online websites, they have options where you can download an offline version and then- Like, there are so many extremists in Bitcoin, right? Of course. This is like the, the blessing and the curse. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "12:28",
      "start": 748.0,
      "text": "Yeah."
    },
    {
      "speaker": "keith_mukai",
      "time": "12:28",
      "start": 748.0,
      "text": "Right? Like it's good that they exist, but oh my god, they're a pain in the ass. and so like, they're like, \"Oh, an online site, you know, that's terrible. You gotta download the offline version, you gotta install Tails, you gotta have a, you know, a, a, a laptop that has the Wi-Fi card ripped out of it, and, you know, blah, blah, like These are test rules, you're gonna, they're disposable. Like, you're not gonna use them for anything. It's just like, you just verify, does two plus two equal four? Yes, cool, right? You're not counting on these websites, or rather, you're not counting on their, I, I don't know. You're not giving them anything useful that they could then be malicious with, because you're just throwing these test rules away. And so, like, if you start thinking about, like, from the attacker side, let's say I'm the attacker, right? I've written malicious code into a SeedSigner. So I know, right? I, I'm right now lying to you, Stephan. Right? I'm trying to trick you, right? Double-pod the play. Yes. Like, verify your roles with an external device, and knowing that, I'm like, okay, so my evil code is gonna be like, okay, do the real result the first time, do the real result the second time, third time, My attacker, a fake seed that he actually"
    },
    {
      "speaker": "stephan",
      "time": "13:43",
      "start": 823.0,
      "text": "had, it was the long con, it was all part of the retirement attack, right? Right, right. So, yeah. But, but so if you do,"
    },
    {
      "speaker": "keith_mukai",
      "time": "13:50",
      "start": 830.0,
      "text": "if you do one set of test rolls and verify, that's a good start, but I wouldn't stop there. Do a second round. Okay, we're getting better. Do a third, you know, it's up to you how many rounds of tests you wanna do and, and show that, that you're getting the same results every single time. But at some point, no matter how clever I think I am as the attacker, I just, I can't guess which round you're gonna do it for real. And, and for most devices. There isn't even a memory to know, like, \"Oh, this is the seventh time, this is the time that we should want to get in.\" This is the one to get in, yeah, yeah. Yeah."
    },
    {
      "speaker": "stephan",
      "time": "14:27",
      "start": 867.0,
      "text": "Right. And, the other thing is it's a layered thing, right? Because you might be dice-rolling different components in your multisig setup, right? Like theoretically, if you're, if you're, if you're going, you know, properly secure, you're doing like multi-vendor, multisig, and this might be only one of the dice part of the approach, right? But now, let, let's put it this way, I also think it's fair to point out that if you make it too crazy, complex, involved, less and less people will do it, right? So yes, many of us might agree that, hey, multisig is, you know, a good thing, multi-vendor multisig is kind of what I see as a good process to, to get to for larger amounts, but at the same time, people could argue back, look, the truth is, there's a lot of-- there are millions So how do you kind of have that balance then of, having an approach that people will actually do?"
    },
    {
      "speaker": "keith_mukai",
      "time": "15:26",
      "start": 926.0,
      "text": "Well, the, the beauty is optionality. So, you know, every device supports Two, three, multiple different ways of generating your seed. So most retail devices, they have a built-in RNG, and the default mode is you just trust their built-in RNG. And I, I, I wanna be I don't wanna demean the RNG method. I mean, obviously it's the big boogeyman of the last couple weeks, but I earnestly believe that the, like, the surviving hardware wallet companies, like, you know, they are, they are, Putting in a crap ton of effort and engineering talent to make sure that these RNGs really are providing like sufficient entropy to, to protect your seed. So I think it's a totally viable option. It failed spectacularly and horribly in one specific case, but the industry as a whole has been secured by these RNGs, you know, since Trezor's first beginning. Twenty thirteen, Trezor, yeah, yeah. so I don't wanna demean RNGs. Yeah, I think for the, for the ninety percent of users that buy a hardware wallet, that's the option that they're going to take. And that's, that's fine for them. I would, I would ideally want them to at least understand the trade-off that they're making, this like convenience versus verifiability versus, you know, making something like the Coldcard bug being impossible to screw them over. But I don't, I, I've no- misconceptions. The majority of people are gonna want the built-in easy mode, and that's totally fine. But every wallet also supports, you know, the word picking and just calculating your final word. So, and that's like, you know, there's different ways to do the word picking. Like I said, you could do these dice worksheets, which I think they're all kind of horrible. Just 'cause the, the steps involved in these dice worksheets, it's like, do a roll, if it's even, go to this page. Do two more rolls, but if it's bigger than a five, becomes like a choose your own"
    },
    {
      "speaker": "stephan",
      "time": "17:37",
      "start": 1057.0,
      "text": "adventure. Turn around three times and touch your toes, and you know, like- Right."
    },
    {
      "speaker": "keith_mukai",
      "time": "17:41",
      "start": 1061.0,
      "text": "And, and like, no one step is horrible, like no one's gonna be like, \"Oh, I can't tell odd from even,\" right? Like, I, I don't wanna exaggerate that way. But it's just enough steps, and, and each step is slightly different, it has its own rules, and like- As a programmer, I understand why those steps are different at each phase, but just as a user coming into it blind, I mean, like, there are people pushing back on, on my, my article saying like, \"Oh, normies will never do 99 rolls.\" I'm like, \"Okay, that's fair.\" But then on the other side, you've got people coming at you saying, \"No, you've got to do this step and that step and that...\" You know, they're making it more complicated. So like, you're never gonna make everybody happy in Bitcoin. It's impossible. Of course. And it shouldn't be possible, right? Because everyone has different priorities."
    },
    {
      "speaker": "stephan",
      "time": "18:33",
      "start": 1113.0,
      "text": "So what's your thought then on some of these lookup tables? So as an example, like I just did recently an interview, I, I recently did an interview with, Blockstream, one of the guys from Jade, and Right? And now, I think they've got some new methods that they're adding, but, previously they had, it was a method where you got two D sixteens and one D eight, and it's a lookup table. So you, you roll the three dice, and then you read off those, and then that corresponds to one of the two thousand and forty-eight, bit thirty-nine words, and then you do your eleven words that way, and then the device calculates the twelfth word. What do you think on that method?"
    },
    {
      "speaker": "keith_mukai",
      "time": "19:08",
      "start": 1148.0,
      "text": "So I, I don't, I don't know, the, the, the Blockstream, the Jade engineers. so I, if, if you all are, are listening to this or seeing this, like, please understand, I, I mean this lovingly. but that is just like such the nerd Blockstream way to do things. It cracks me up. 'Cause, like- For, for the people saying a normie won't do ninety-nine dice rolls with a regular pair of six-faced, you know, six-sided dice, right? A regular cube. For Blockstream to say, \"Okay, step one, go buy a D&D dice roll set,\" right? Like a normie, a normie doesn't even-- has never heard the phrase D sixteen. They have no idea what that means."
    },
    {
      "speaker": "stephan",
      "time": "19:52",
      "start": 1192.0,
      "text": "That's, that's a fair point. That's true. but yeah, to be fair to them, I think they did recently come out with some other methods, like And even some tarot thing, like, kind of like astrology kind of thing, I don't know, whatever. I didn't really look too much into that, but, you know, people into astrology, maybe for, for the women in our, the females in our lives who are into astrology, maybe that's one way to get, hey, hey babe, come and let's do this, get your astrology cards out and we'll do our seed generation that way. Anyway, so I guess the point is there's different methods to get the entropy. It's useful if you But ideally, it's a layered approach. That's at least how I'm, I'm seeing it. let's switch now to talking a bit about on the SeedSigner side of the house. So, you know, give us, a bit of an update, what's kind of the latest with SeedSigner? actually, sorry, before we do that, just quick, you know, one minute overview for people who've never heard of or used SeedSigner, give us an overview there for lis-- for those listeners who are new."
    },
    {
      "speaker": "keith_mukai",
      "time": "20:52",
      "start": 1252.0,
      "text": "Yeah, so SeedSign Developer, but I'm a volunteer, so nobody's paying me to, to work on the project. So it's a, see, here we go. There is a SeedSigner. it is a Bitcoin signing device where you can create private keys, you can set up, you know, wallets in software like Sparrow, BlueWallet, you know, whatever, and you can sign transactions. But what's different about SeedSigner is that it's built from off-the-shelf parts. So instead of going to, you know, Ledger dot com or Trezor dot com or Trezor dot io, whichever it is, there's no retail company to buy it from. Or at least you have the ability to avoid any sort of seller. There, there are like, third-party sellers that will preassemble a SeedSigner for you, And if you buy from them, you know, you're making a, kind of a security trade-off. but the ideal is you source the parts yourself and they're off-the-shelf parts that have nothing to do with Bitcoin. And so you're not putting yourself on any mailing list that can get leaked, you know, that makes you a target as somebody who, you know, like if you're buying a hardware wallet, that's a pretty strong signal that you've got at least some amount of value that you're securing. And if you're home- Your address gets leaked, like it's just, you know, you're, the five dollar wrench attack is coming. Like, even if you don't think you have a lot of Bitcoin, you know, your address gets leaked because you bought a hardware wallet today, and then five years from now, we've got million dollar Bitcoin, right? And so anybody looks back in the past and says, \"Oh, this guy's been in Bitcoin for five years and, and it's worth a million dollars each right now, so let's go attack him.\" But yeah, so the idea is that you can, you can build your own signing device without basically leaving a trace that that's what you're doing. And then the code is open source, you download it from GitHub, you verify the, that the download matches the, the published hashes, and you run it on, on, the device. And so like, like people have asked me, you know, how many people have built a SeedSigner, and the awesome answer is, I have no freaking clue. Because those of us that work on the project, like, we aren't the gatekeepers, we aren't the salespeople, like, we have no idea who is gonna have analytics"
    },
    {
      "speaker": "stephan",
      "time": "23:27",
      "start": 1407.0,
      "text": "tracking how many people are using SeedSigner, obviously, 'cause it's, it's just a, it's a project that anyone can build. Right. and then just talk through kind of the, the basic UX of it, like, it's, you know, you get a, an SD card, you're plugging it in, you're powering it on, and you're, you know, you're Like how it typically works, like it's normally a QR flow, right?"
    },
    {
      "speaker": "keith_mukai",
      "time": "23:52",
      "start": 1432.0,
      "text": "Yeah, so it's, it's fully airgapped, which means there's no physical connection to the computer. it has a camera on board, so software like Sparrow will show a proposed transaction as an animated QR code. You point the camera at it, so now that transaction is on board. You review the details of the transaction, make sure that, like, you know where all your sats are going to what address, what change is coming back to you, all of that. and then when you sign the transaction, the screen shows you your signature as an animated QR, so then you show that back to the, the laptop camera. Like the"
    },
    {
      "speaker": "stephan",
      "time": "24:28",
      "start": 1468.0,
      "text": "Sparrow or the Nunchuk or something like this. Yeah."
    },
    {
      "speaker": "keith_mukai",
      "time": "24:31",
      "start": 1471.0,
      "text": "Yeah. And then, and then Sparrow and Nunchuk, they've got all the information they need, they've got the signature to authorize the transaction, so then they do the broadcast. But your private key has only ever interacted with the SeedSigner, it's never been on your online device. and- And the SeedSigner itself is called stateless, which means when you pull the plug, everything that you loaded into it was only stored in RAM, and RAM doesn't survive when there's no power. And so the idea is like If, if I transact, you know, my life savings, and then I unplug this and I set it down, and I forget, and I walk away, and then the evil, evil maid runs in and, and she's like, \"Oh, he left it out,\" and, you know, grabs it and runs away. There's nothing on it. There's nothing for them to recover. and the other nice thing about that is, so, okay, you have to load your, your seed on, you know, new each time you power it up. But it also means that the device doesn't care which seed you load onto it. And so, as a, as a way to get started in multisig, just for testing purposes, you can use the device to create three new keys, set up the wallet in Sparrow, and then play the role of, okay, right now I'm gonna be Alice, so I scan, you know, I load in Alice's key, sign the transaction, blank the device. Okay, now I'm Bob, scan in Bob's key, you know, do the transaction. whereas with a traditional hardware wallet, it stores one key, you know, it locks it tight inside the device and protects it. But if you wanna play with multisig, then you need multiple devices. And depending on the device- Right. So it's a convenient"
    },
    {
      "speaker": "stephan",
      "time": "26:16",
      "start": 1576.0,
      "text": "learning educational tool in that way. And then I guess the other thing that's kind of a SeedSigner style, let's say, is this idea of the SeedQR, which I believe some other wallets have actually adopted that, or at least it's a possibility. Can you talk us through that? Like, as I understand, it's People use like a sharpie and they fill in the pieces and then they can quickly, let's say, ingest the private key or the seed into the SeedSigner so that it can do the signatures for the, you know, in those, let's say, three role, three signing cases as an example. Yeah,"
    },
    {
      "speaker": "keith_mukai",
      "time": "26:45",
      "start": 1605.0,
      "text": "so I mean, the, the, the default SeedSigner build has a tiny little screen, and so you can imagine how much it sucks to have to type in like a twenty-four word seed every time you, you power this on that and you wanna transact with. So the SeedQR format basically transcribes your mnemonic as a QR code that you make by hand. And you have to make it by hand because, well, first of all, the device is airgapped, right? So you can't, you can't like send it to a computer or a printer anyway. and this, I mean, I'm, I'm showing this in front of the screen, right? But if this was like holding real value, you would never do this, 'cause this is, this is like literally showing your- Right,"
    },
    {
      "speaker": "stephan",
      "time": "27:28",
      "start": 1648.0,
      "text": "because instantly people could just download it and, you know- Yeah, swipe it and sweep the money."
    },
    {
      "speaker": "keith_mukai",
      "time": "27:34",
      "start": 1654.0,
      "text": "This is identical to, to showing your twelve or twenty-four words, you know, on a live stream, right? Like you just wrecked yourself. But so you have to protect it like you would your backup phrase. And so like, yeah, I've got this lying on my desk, but there's no value in it, right? If I actually had Bitcoin on this, it wouldn't be sitting naked out on my desk here."
    },
    {
      "speaker": "stephan",
      "time": "27:57",
      "start": 1677.0,
      "text": "Of course, yeah. This is more for the educational or testing purposes in that case. and so I guess, yeah, that's just the way for people to understand that. But then it changes the model in terms of maybe where you keep the devices and where you keep, you know, your SeedQR, obviously Because that, that's the money, that's where it is. So you have to think about that, right? Because you might-- It, it, the thing is, there's no one size fits all, because some people don't have multiple locations to do multisig, and so for them, maybe they are more interested in doing like a passphrase style instead of the multisig style, or, you know, this kind of thing. So it's kind of difficult to give kind of a, you know, one size fits all there. But at least the way you understand it, how would that change where"
    },
    {
      "speaker": "keith_mukai",
      "time": "28:41",
      "start": 1721.0,
      "text": "So, I mean, the, the most important starting point is, you know, we view SeedSigner as a long-term cold storage tool, which, you know, is built for multisig and favors multisig, but it, it can be used with single-sig and single-sig with a passphrase if, if that's your choice. but because it's primarily meant for long-term storage, like I do three transactions a year that require a SeedSigner, right? I'm like pulling things out of long-term storage to unfortunately move to an exchange so I can sell some Bitcoin so I can pay my bills, and I'm just, I'm not, you know, if this was my real SeedQR, I'm just not pulling this out every day, because if you want- If you want to use SeedSigner, you do need this or your mnemonic phrase available. but if you're doing long-term cold storage, that can live in a secure bunker hours away from your house, and it doesn't matter, right? You just drive there a couple times a year when, when you need to move your cold storage. and of course, that's only when you need to transfer out. Like, you can do deposits in trivially with a watch-only"
    },
    {
      "speaker": "stephan",
      "time": "29:57",
      "start": 1797.0,
      "text": "ExPub, et cetera. Yeah."
    },
    {
      "speaker": "keith_mukai",
      "time": "29:58",
      "start": 1798.0,
      "text": "Yeah, but if your use case is- Is, oh, every couple days or every couple weeks I have to do an on-chain transaction, and it's really important that, you know, my seed doesn't get leaked, then SeedSigner starts being not a great option, and something like a traditional hardware wallet where you have the physical protection of the seed living in this device starts making more sense."
    },
    {
      "speaker": "stephan",
      "time": "30:20",
      "start": 1820.0,
      "text": "Yeah. now one other thing, I, I was thinking we, we should chat about the whole, like the so-called evil made sort of evil firmware kind of, like a dark Skippy sk- kind of attack, right? There's like a, I guess back in the day when Michael Flaxman and Stepan Sniegierew were talking about this stuff, it was the chosen nonce attack, and then more recently, like I think some of the Frost Snap guys had this dark Skippy, which is like a biased nonce kind of attack. So I guess Someone comes and changes out the firmware in your SeedSigner to make it do, like, a, you know, leak out the seed through the nonce on the blockchain, which would be really, you know, you can't detect that. Now, I presume, you know, there are defenses like for you as a user, maybe it's like you make sure you put in that SD card with firmware that you know is legit instead of obviously the evil firmware. But can you talk us through a little bit of that and how you're thinking on that from a security, you know, perspective?"
    },
    {
      "speaker": "keith_mukai",
      "time": "31:17",
      "start": 1877.0,
      "text": "Yeah. I The miner is built from off-the-shelf parts, you just don't have the built-in hardware protections that a dedicated hardware wallet has. Like, there's no, there's no getting around that. and certainly for huge chunks of, of people, that's, that's a, that's a non-starter, that's unacceptable. Like, they need more physical hardware device protections, which is totally fair. In the SeedSigner world, all of the code runs from the SD card. And so, yeah, if you leave this lying around, this, it's hard to see, but this is the SD card port, if you leave this lying around, and the evil maid, all she has to do, take the card out, put a very similar-looking one in, and now you are screwed. You have no defenses. You've lost, period. Like, it's game over. And so, I mean, my defense against the evil maid is I have a messy house, and there are no maids coming in here at all. not everyone has that, that, you know, luxury. I, I don't have a wife or a, a, a live-in girlfriend here to, to, you know, force me to, to tidy up. But, and, and like, if somebody asked to borrow my SeedSigner, I would take the card out, I would give it to them without a card, and I would give them the, the step, the instructions, like, okay, you need to get your own SD card, you need to download the SeedSigner firmware. Firmware is kind of a- Messy term for us. download the SeedSigner release, verify the release, flash it to the SD card, and then you're good to go. And on the, on the flip side, if they return the device to me and there's an SD card in there, like I just have to assume, right? Like, chuck it. And also the, the releases are like twenty five megabytes, so when you flash the SD card, it literally takes seven seconds from the point you hit go, alright? So the most paranoid people They can just always re-download the entire release, re-verify the hashes, re-flash a brand new SD card, and put that one in, and they're totally fine. And then the only level of attack, of attack beyond that would be if, you know, if the evil maid is actually employed by the NSA and it's not just the SD card, like that's, you know, that's"
    },
    {
      "speaker": "stephan",
      "time": "33:44",
      "start": 2024.0,
      "text": "JV life, right?"
    },
    {
      "speaker": "keith_mukai",
      "time": "33:46",
      "start": 2026.0,
      "text": "No, she's gonna open this up. And she's gonna modify the board and solder on, you know, some secret chips or whatever else, like physically alter the, the hardware. but, you know, at some point, like, I don't know. Like, I, I expect a seatbelt to protect me in the car, but if something hits me at two hundred miles per hour, I don't expect the seatbelt to save me. So like, at some point, like, there's just a limit to what, to what you can reasonably worry about."
    },
    {
      "speaker": "stephan",
      "time": "34:16",
      "start": 2056.0,
      "text": "And so, I think to be fair, and, you know, I don't, you know, think it's, it's a total non-starter. I think it's more like, the way I think about self-custody is I would, I But yeah, I think it makes sense, like as, as you said, education, testing, and also as part of a multisig, I can, I can see that, right? And the idea is, you know, if you're doing multi-vendor multisig, the idea is that the, they're different kinds of devices, they may fail or break down in different ways, but because we're using multisig, like two of three, three of five, or whatever your quorum is You can, you know, it gives you that flexibility of like even with one catastrophic error, you may not necessarily lose your coins because you've, you know, you, you, you built in that safety by using multi-vendor multi-sig, at least, that's at least how I'm seeing it. but I'm curious how, how are you seeing that? Like, where are you at on the whole, you know, multi-sig versus, let's say, passphrase or single-sig? Like, what do you, what, when someone asks you, how do you typically break it"
    },
    {
      "speaker": "keith_mukai",
      "time": "35:16",
      "start": 2116.0,
      "text": "I have really faded on single-sig plus passphrase. Like, I, it's an okay, Improvement, but single-sig plus passphrase is basically two secrets, right? The your, your coin mnemonic and your passphrase. If you lose either one, you're screwed. And so if you have two must-have secrets, I just don't think multisig is that much harder to go to a two of three, and with a two of three, you've got redundancy built in, so now you can lose one of your, you know, one of your three seeds and still recover."
    },
    {
      "speaker": "stephan",
      "time": "35:57",
      "start": 2157.0,
      "text": "Yeah. So basically you lean towards the multisig side then?"
    },
    {
      "speaker": "keith_mukai",
      "time": "36:00",
      "start": 2160.0,
      "text": "And I, and I just don't think it's that much harder. Like, multisig has the one big gotcha, which is you have to store your descriptor, which has the, the three xpubs that make up your two of three. If you don't have that, you're screwed. But the descriptor doesn't have anything secret. Like if your descriptor leaks, then you have a privacy loss, but nobody can steal your funds. And so it's pretty easy to just store a copy of your descriptor with each of your seeds. Like the whole system depends on two of your three seeds surviving, which means you have two, at least two copies of your descriptor surviving also. so I just, yeah. I, I just think it's an easy problem to solve."
    },
    {
      "speaker": "stephan",
      "time": "36:43",
      "start": 2203.0,
      "text": "Yeah. and I guess one other question around the multisig, so I don't know the formal name for this, but I, you know, I just call it registering the multisig quorum, and obviously that's a step that you do when you're doing multisig, on most devices, I believe Trezor actually doesn't have it, because they kind of have a different philosophy about it, but how does that work with SeedSigner then? Because you would have You try to put that into the SD card so that you can-- it, it has the, the quorum."
    },
    {
      "speaker": "keith_mukai",
      "time": "37:14",
      "start": 2234.0,
      "text": "So, yeah, so right now, the best practice is when you create the wallet, obviously you're going to, backup the descriptor. And Sparrow has a really great option where you can, you can backup the wallet as a PDF, and the PDF has all of your xpubs, but it also has a QR code of your"
    },
    {
      "speaker": "stephan",
      "time": "37:33",
      "start": 2253.0,
      "text": "descriptor. You're scanning that p-PDF with the SeedSigner to ingest the multisig quorum. And then now it has kind of, oh, I know the X pubs of my other cosigners, and now I can check my change addresses to make sure that I'm not being ransom attacked or et cetera. Yeah."
    },
    {
      "speaker": "keith_mukai",
      "time": "37:49",
      "start": 2269.0,
      "text": "Yeah, exactly. And- You know, that PDF, again, I said that the descriptor is a potential privacy leak but not a security leak, so I have no qualms using Sparrow to generate that PDF and then sending it to my printer. so yeah, I just, I just print it out and then, you know, I go to my co-signers and I say, \"Okay, here's a key that I need you to hold onto, and here's this, you know, descriptor thing. You don't even have to understand what it's for, just hold onto both of these for me.\""
    },
    {
      "speaker": "stephan",
      "time": "38:19",
      "start": 2299.0,
      "text": "Gotcha. And then is it also possible, I presume it is, to ingest the descriptor via the SD card?"
    },
    {
      "speaker": "keith_mukai",
      "time": "38:25",
      "start": 2305.0,
      "text": "Not right now. one challenge we have is There's so many things that are like, they're almost like annoying marketing or PR reasons and not technology, but we are hesitant to We're hesitant to write any data to the SD card, 'cause that feels scary, 'cause, well, if you can write this to the SD card, then you could write my private key to the SD card, and, you know, that's not the model that Seed Center, wants to support. but reading something in from the SD card feels safer, but even then, I think we would only do it if it was a different card. So you boot up the device with the release code on the SD card, and then as soon as it boots, it actually shows you a message that says it's now safe to remove the, the SD card. So once you remove it I think eventually we will get to a point where you can then insert a data only SD card that has things like your descriptor on board."
    },
    {
      "speaker": "stephan",
      "time": "39:28",
      "start": 2368.0,
      "text": "Gotcha. Yeah. So I guess for now it's mainly the paradigm of you scan in the descriptor each time you're doing it. and so then that kind of necessitates a little bit more of the trust on the, the printer side of it. Again, some people wanna go really paranoid about who's hacked your printer and all this stuff or your Wi-Fi, 'cause if you're printing that, but, you know, it's your, as you said What's the right model, what's right for them, and it could also be that, depending on what you're doing it with, you might be able to, like, let's say you had Sparrow on the laptop and you take the laptop to the signing location, you might be able to ingest it from that too, right? You might just literally turn around your Sparrow and ingest, you know, let's say your laptop and ingest it that way, right?"
    },
    {
      "speaker": "keith_mukai",
      "time": "40:11",
      "start": 2411.0,
      "text": "Yeah, I mean, you have to be careful. The, the benefit of printing the descriptor right in the moment that you create the wallet is that, assuming that you started that process from a clean state, as in your Sparrow is legit, it doesn't-- you're not running a malicious version. Then you-- that's what we call the known good descriptor, because that was created in the clean state. Gotcha. Now, fast forward in that"
    },
    {
      "speaker": "stephan",
      "time": "40:39",
      "start": 2439.0,
      "text": "case, the malicious Sparrow wallet, let's say, giving you like a bad descriptor, let's say. Right."
    },
    {
      "speaker": "keith_mukai",
      "time": "40:44",
      "start": 2444.0,
      "text": "So over time, if your system is compromised and now, now you're running an evil Sparrow. If you trust its live descriptor display, you get what you get. and so again, it's, it all hinges on you starting from a clean environment, but that's kind of as far back as we can go in terms of establishing trust in, in the descriptor."
    },
    {
      "speaker": "stephan",
      "time": "41:07",
      "start": 2467.0,
      "text": "Yeah. Yeah. And again, at some point, like, 'cause again, we're kind of, again, into the usability versus more security, because for usability's sake. Maybe it is better that people put a little bit of trust there so that they use multisig, full stop, instead of doing the less bad thing, like the, which is kind of maybe the worst step of like going to single-sig with no passphrase or single-sig passphrase not in a multisig. So it's kind of, well, was it better that they did multisig in a slightly imperfect way than doing, you know, single-sig? and just being more vulnerable, full stop. So I don't know. Yeah. That's a question for listeners to, you know, you have to think about your own trade-off of like, what is actually more practical for me in the real world, you know?"
    },
    {
      "speaker": "keith_mukai",
      "time": "41:50",
      "start": 2510.0,
      "text": "Yeah, that's, and that's something I've, I've had to learn over time, like, you know, in, in the SeedSigner Telegram group, people are, are always asking these questions, which is better, which should I do? And over the years, I, I, I came to basically where, where you're at, where it's like, it's so context dependent. Everyone's circumstances are different, everyone's priorities are different, everyone's technical skill is different. so what's best for you isn't necessarily gonna be what's best for me, and so there's, there's just no way to say this is better than that. It's really just like, I, I started asking instead. Like what are your goals? What are the, what are the top risks you're trying to mitigate? If it's, you know, I wanna make sure that my wife will have access to the funds if I die. Like, okay, that pushes us in, in one specific direction. If somebody else says, \"Oh, I wanna make sure that if the five dollar wrench attackers come for me, that they can't get to my stack,\" that's, that's almost the opposite direction because that makes it harder and more opaque and more obscure, to be able to access your funds. So there's just, there's no one size fits all"
    },
    {
      "speaker": "stephan",
      "time": "43:01",
      "start": 2581.0,
      "text": "Yeah, so I guess one other question, I guess before we finish up, is obviously all the Coldcard stuff spooked a bunch of people, and there are some people saying on the extreme end of, \"Oh, it's over self custody, everyone's gonna go to ETFs and custodial stuff.\" On the other hand, you've seen more people, let's say, a renewed interest in multisig. because of, you know, this increased security that you can get, or at least fault tolerance. Where do you land on some of that, and do you see that as like, you know, is it important to-- Yeah, I guess let, let me put it there. Do you-- Where do you land on that kind of, argument?"
    },
    {
      "speaker": "keith_mukai",
      "time": "43:37",
      "start": 2617.0,
      "text": "Yeah, well, I mean- So, let, let me, let me take a step back, it, by way of answering your question. So since, you know, the last three weeks, it's just been horrible for everyone, as, and certainly, you know, for anybody, any programmer working on a wallet or anything that secures Bitcoin, it's just, it's like we're all the, what's the phrase? We're all the fish in the barrel right now, like you, we're all easy targets. anyone, anyone who points an AI at us can, can find all of our Our flaws. so SeedSigner has some issues that we're patching, but nothing like dire enough, like, let me rephrase, if there was a dire emergency, we would have announced, like, \"Oh my God, this is a big deal,\" you know, and we'd have announced like steps to keep people safe. So we, our, our sense is that there's nothing like that in SeedSigner, but there are really important things to fix that I've been like working on nonstop. For the last three weeks. But at the same time, I've been spending an insane amount of time on things like this dice roll write up because the whole incident just showed, like. Just, just how lacking the average person was in, in their understanding of, of just how everything works. Like the average person, you know, they watched a BTC Sessions video, who is amazing, he's great. And they followed the steps that he laid out, but they just didn't understand what the steps were or what they meant or how it secured them. And so I've been spending a ton of time on education, you know, trying to write these explainers, trying to like, it, it started out as just trying to document what SeedSigner does so that somebody who was scared could kind of trace through and, and read in like normal human language, how this works. And what they can do to reassure themselves and, and verify. but it's really broadened out to, you know, so now this dice roll document is like the entire universe of dice, of the dice roll ecosystem, you know, across Bitcoin. Because I think education is just the most important thing. I don't know what happens to self-custody, like it's not, I- I'm just, I don't, I don't have a view, you know, at that like ten thousand foot view and, and understanding of, of how people outside of my bubble, you know, understand these things. all I, all I know is that People need to level up. They need to understand things better than they did, and obviously not everyone will, but for the people who are motivated, for the people that want to stay in Bitcoin but need to get over their fears, like I'm trying to help produce information, you're producing information, to help them get more educated, 'cause the, like Like when you're not a programmer, when you're not technical, there's no way to assess like relative levels of risk, right? Like everything sounds scary, everything is a black box, and, you know, I'm trying to at least help them understand, like, okay, there are still risks in this corner. But they're really not that bad, and there are things, concrete things you can do to assure yourself that there isn't some mystery hiding, you know, risk in there. Whereas like, yeah, there are other areas that are like much harder, more mysterious, harder to prove for yourself, and like- You know, like, no, I don't expect everyone to understand like elliptic curve cryptography, you know? Like, I barely understand it. but I understand dice rolls, and I think an average person can understand dice rolls."
    },
    {
      "speaker": "stephan",
      "time": "47:28",
      "start": 2848.0,
      "text": "Yeah. I guess just zooming out. Yeah, as you said, this kind of, this question of like, is everyone, people, are people just all gonna go ETF custodial? Like, to, to the point you said, everyone's taking risk every day. Lots of people have money in their fiat bank accounts or in fiat, you know, investments, that they take risk on those too, right? You could get locked out from your bank account, you could get shut down, you could get funds seized, stolen, property seized or stolen. All of these risks do exist today. We don't like, you know, run, and yes, there, there will be that question for people of whether they buy ETFs or put Bitcoin in custodial products, but then you're still trusting that they get the entropy right, you're still trusting that they get those things correct, and so you, you still have to think about how are you gonna spread your risk, even if you do have some ETF or some custodial stuff, are you gonna keep some in self-custody? And then once you're in self-custody world, well, then it's that question of, okay, are you gonna do single-s Or maybe even multisig with a passphrase, like, I mean, these are all options, but I think the key point that, you know, for me, I think it's that if you do-- Yes, there's a small increase in complexity for multisig, but it gives you this fault tolerance, and I think that's, that's something interesting, and most people haven't really got that yet, because maybe they've heard about multisig, but it hasn't been put in a simple enough way for them to sort of really understand, \"Oh, no, if I do this the right way, Instead of the other way around where people are kind of worried that it's too complex for them. So yeah, I guess that's kind of where I'd leave it. any other, yeah, any closing thought from yourself and where can people find, SeedSigner and find you online?"
    },
    {
      "speaker": "keith_mukai",
      "time": "49:13",
      "start": 2953.0,
      "text": "Yeah, I mean, just, just to, to wrap up on that thought, like I think everybody thinks about this as these like monolithic decisions, right? Like, I can't do, I can't move to multisig because it's just, it's too big, and if I move my entire stack there and I screw it up, I'm screwed. Like, don't move your entire stack, you know? Like, take these baby steps. Like, there's a whole spectrum. Like, if you wanna do multisig but you don't wanna do the setup yourself, collaborative custody is great, Unchained, Casa, you know, there's all these other anchor watch, right More products and services that are offering collaborative custody. And yeah, okay, that's not like the most self-sovereign, but it's better than having all of your risk concentrated either on yourself or on the ETFs or, or somewhere else. And again, don't move your whole stack. If you are a hundred percent in the ETFs, move twenty percent of that value into collaborative custody. And then once you get comfortable with that, on your own pace, at your own time. Start experimenting with setting up your own multisig if you wanna go that direction. And set it up, move a tiny amount, screw it all up, right? Like, oh god, I just lost twenty dollars with a Bitcoin. Practice recovery, right? Yeah. Yeah, right? Like, like people are so afraid to just try and fail, but like, you can do it with almost zero consequence. So, you know, just like baby step your way there, and maybe you'll find, like, like you were saying, they're like, \"Hey, multisig actually isn't that hard.\" Or maybe they say, \"You know what? I screwed this up three times in a row, it's not for me. \" That's totally fine. But it's, it's so easy to make these little steps and, and just moving, you know, either tiny value or just like a part of your stack. Like my whole goal is not to have all of my eggs in one basket, so I have multiple multisigs and I have some collaborative custody setups as well, 'cause like At, at this point, I'm the single point of failure. And so how do I fix that? Oh, I get, you know, Unchained or Casa or whoever else involved in the mix. so just You can have baby steps into multiple small solutions, and if they work out for you, you can, you can grow that portion of, of where your stack lives. You can ease your way into these things. but yeah, I'm, I'm Keith Mukai on Twitter. I should have started life as an anonymous developer, but I didn't, I screwed that up, so I'm, I'm totally doxxed. and go to SeedSigner dot com to learn more about the project, and there's a link there into our Telegram group. Which is just an awesome place to ask all of these sorts of questions. and yeah, that's it. Read, read the Dice document and, stop spreading, you know, stupid recommendations about how to do dice rolls correctly."
    },
    {
      "speaker": "stephan",
      "time": "52:05",
      "start": 3125.0,
      "text": "Excellent. Well, great to chat, Keith, and, thanks for joining me. All right, thank"
    },
    {
      "speaker": "keith_mukai",
      "time": "52:08",
      "start": 3128.0,
      "text": "you."
    }
  ]
}
