NODE ONLINE
EP 29
slp@node:/transmissions$ open --transmission SLP29
TRANSMISSION_DETAIL

TRANSMISSION SLP29

Samourai Wallet, Bitcoin privacy software that Silicon Valley would never build

with Stephan Livera

DATE 25 October 2018
DURATION 01:08:58
GUEST Stephan Livera

One of the pseudonymous founders of Samourai Wallet joins me in this exciting episode to talk about Bitcoin privacy techniques that are applied within the wallet and upcoming improvements to their Bitcoin wallet app. Anyone interested to learn more about how Samourai Wallet helps protect privacy will truly enjoy this episode.

listener@future:/timestamps$ list --chapters
CHAPTER_INDEX
    listener@future:/transcript$ decode --transmission SLP29
    TRANSCRIPT_BUFFER DECODED

    Welcome to the Stephan Livera podcast.

    Hey guys, welcome to the show. This is Stephan Livera podcast episode twenty nine, and this, my guest today, it's really special, it's like super cypher punk. It is samurai wallet dev, so welcome to the show.

    thanks, it's good to be here. I'm a big fan of the podcast.

    Oh, thank you very much. Yeah, I'd like the, work you guys have been doing. So, just for the listeners who are a little newer, many people in the Bitcoin space operate under a pseudonym, and obviously, as I wanna not dox people, I, you know, if they're, if they're coming on the show under a pseudonym, it's under the pseudonym. So, just a bit of a quick intro, Samurai Wallet is a really interesting project, and I've been following it for some time now, and I have,

    People good Bitcoin wallet. Now, the developers of Samurai Wallet definitely have not shied away from controversy and they will take what you might call a more hardline stance on privacy, which is also pretty cool. So maybe we can just start with that one, Samurai Dev. with the ethos and the mission and, and privacy, I noticed on your website you've got this tagline, "We are privacy activists who have dedicated our lives to creating the software that Silicon Valley They will never build, the regulators will never allow, and the VCs will never invest in. We build the software that Bitcoin deserves. Do you wanna just tell us a little bit more about this tagline?

    yeah, sure. but, be-before I do that, just, I just wanna be clear, I'm actually, Samurai Wallet, and Samurai Dev is, who's at Samurai Dev on Twitter is, is, is the primary dev. So I don't do, I don't do the primary dev. Samurai Dev and I started Samurai Wallet together, back in 2015, and, we wrote that tagline together as kind of our, our mission statement. And it's, it's, it's, We wanted to make sure that however big the project got and however, however, many people used it, we stuck to our initial vision, and The vision that we, we had for a Bitcoin wallet, just by design, w-would not be interesting to, to VCs. however, we also had our own negative experiences with, VCs in the past, both separately and together, so, we decided that's not something that we wanted for, for this type of product and this type of project.

    Right, yeah, yeah, and I noticed that, you guys are, are part of what is called the Zero Link framework, which is basically about providing additional privacy in Bitcoin. and, one of my prior guests was Adam Fitzor, who is the CTO and the lead developer of Wasabi Wallet, who is another, wallet, who are, you know, software, who are part of the Zero Link framework. Do you want to tell us a little bit about how you think in terms of breaking heuristics and how that helps in terms of- From a privacy point of view.

    Yeah, sure. Yeah, so Zerolink, was a, was a, is a great, you know, framework. Adam, Adam came, got in contact with us, a year ago, I believe, or a little less than that. And, and asked Samurai Dev if he would be willing to, to contribute and work on the, the framework. So we, we were totally thrilled with that. We like, we like when people reach out and want to work together, so we were, we very happily, collaborated on the zero link framework and, and, started work implementing it immediately. so our, our,

    Our implementation of the zero link framework is, is called Whirlpool.

    and it's one of the Well, it's kind of like the, the ultimate, tool in our, in our suite of tools. all of our tools are designed to break the heuristics used by blockchain analysis and, and, and more generally, kind of blockchain spies, I would call them.

    the idea is, I guess, if, if you subscribe to the idea of taint, so some, some transactions are tainted, some UTXOs are tainted, quote unquote, and I use very heavy quotes. then we're gonna, we're gonna play your game, but we're gonna make sure that everyone's tainted, that there is no untainted. And the way you do that is by attacking the assumptions that, that, these analysis companies have been making because wallets have been making it dead easy for them to do that. And by attacking those assumptions, you really throw a spanner into Into the main driving forces of, of how they create the, this taint, quote unquote, and how they create blacklists. so, I mean, it, it, it, it's fun, it's fundamental to the fungibility of the token, and that's why, you know, from an ideological standpoint, we, we, you know, we're, we're involved. but from a, a utility standpoint The value of the token is, fundamentally undermined if there isn't some sort of fungibility aspect of this thing.

    Right, and then there are multiple ways that your privacy can be broken, right? So obviously, just straight on the transaction layer, depending on obviously the heuristics that are applied, such as if multiple UTXOs are merged into one transaction, then chain analysis companies will try to assume that, oh, yes, this, these two UTXOs must have belonged to the same person. And then there's also the network attack level. So do you wanna talk a little bit about, you know, what are some of the ways that users- Users can, you know, try to use these tools to defend their privacy.

    So, sorry, can you, can you kind of repeat that? Yeah,

    so just talking about how you, you have to consider the different angles by which you can be, let's say, fingerprinted or de-anonymized. maybe you could talk a little bit about, you know, the network attack angle or if there are any other kind of angles to think about. Oh,

    there's, there's all sorts of angles. The primarily, honestly, the primary way the chain analysis, and, and general intelligence gathering works on, on the blockchain is, is, is off blockchain. It's leaving social metadata around. it's connecting addresses to yourself by putting them on Twitter, or on your, you know, Bitcoin Talk signature. all of this stuff is, is considered in a good analysis platform. it's not, it's not just like you say on-chain stuff. I, I mean, it can come down to, to, you know, fingerprinting the type of,

    Wait, the way you're connecting to the network, it could, Tor, VPN, if you're using a known VPN, all this stuff, ties into building a social profile. of yourself, and these are, these are all different, different security concerns and privacy concerns. What, what our main focus on is, is on, on-chain privacy. So if we, what we, what we want to need to focus on, or what Samourai wants to focus on, is the user being able to create transactions that,

    prevent, prevent them from being targeted or, or, yeah, well, yeah, targeted, like de-anonymized. Not even, not even de-anonymized, just targeted. You know, think of it this way, you, you are an innocent Bitcoin user. You are just a guy who received some Bitcoin, and little d-- did you know that this Bitcoin that you received from, a buddy, you know, he, maybe it's your first Bitcoins, you know, are somehow consi- That are tainted because they're, they, they're, they're connected to the Mount Goats coins in some, in some capacity. Well, you're gonna get binged for that, you know, the minute you go and send those to Shapeshift to buy, you know, your first Litecoins, which you would probably do, as a noob. That's it, shapeshift, chainalysis kicks in and that's locked, and now your experience is completely negative, but you're innocent, you know, entirely. Samurai's goal is to prevent that type of thing from happening.

    Yeah. And I think another thing you guys have done recently is the digital removal of fiat, which I thought was really controversial, but at the same time, actually a good thing once, once you think about it. Let's talk a little- A little bit about that. I know you copped a bit of flack online for that, less than I thought I would. Yeah. Oh, really? Okay. You thought you'd get more?

    no, it was actually, yeah, the, the response was a lot more supportive than I ever would have guessed. I thought it was gonna ruffle a lot more feathers than it did. look, there wasn't, there wasn't a huge-- we weren't trying to make a big point, we weren't trying to say that, you know, we need to drive, some sort of, of circular economy or something like that, and you should only think in terms of BTC, because that's not the reality of the real world, you know? everyone at Samourai, has been, has been working for and living off of BTC, for, for many years, and we, we understand the implications of the real world and using this However, you know, I've noticed over time that the education-- we always say it's an education issue, and then, and we blow it off as, "Oh, it's an education issue" when it comes to new users and needing to wrap their mind around These, these incredibly c-complex concepts that Bitcoin comes with, and we take that for granted sometimes, as, as users who have been involved in this for a while. So we, we always, you know, that's, it's an education issue, but the issue is no one is educating. And by leaving fiat in the wallet, that's, that, in the Bitcoin wallet, that's acting as a crutch for the user where they never have to learn. And you would, I mean, we've had users who have been using Samurai Wallet for, you know, seven, eight, nine months, ten months, even a year, in the extreme circumstances, who would have emailed support and have talked, you know, in complete fiat terms. You know, "Oh, I sent two fifty to this guy, two dollars fifty to this guy, but now it's three, three seventy-five. What's going on?" you know, or they, they send the wrong amount to a, a BitPay QR code, in a different-- or they send, yeah, they send some amount to a BitPay QR code in a different wallet, and when they come back into Samurai Wallet, it shows a completely different fiat value, they think they're being ripped off. And you would expect that from a very new user, but from a user who's been involved for twelve months, it's, it's, it's kind of unacceptable. so our rationale is, look, we're not a USD wallet, we're not a fiat wallet. We'll, we'll stop reinforcing that within the wallet and rely on the merchant to set the price, which is what happens anyway today. And what was happening anyway before, and which was the cause of most confusion, because the, the two prices never con-- you know, or very, very rarely, converged. So some, it was always off, you know? so we just made, it was very much a practical decision. It was like, "Hey, we need to streamline things, we need to get support, support requests down." And, and on those metrics, it's been incredibly successful. Support requests are down, in terms of the fiat issues. That's, that's been resolved, as far as we're concerned. Yeah. And so what,

    what sort of customer support, what sort of problems were you having? Were, was it customers coming to you saying, "Oh no, you sent the wrong amount," that kind

    of thing? Well, so there's, there's plenty of that. There's plenty of that, but there's also plenty of legitimate support requests that were complicated. By the user referring to the amounts that they sent or if, let's say the issue was, "Oh, I don't see, you know, my change or something like that in my wallet." Usually it's like a tour issue or something. needs to be re-rescanned. but it's very difficult to determine, you know, what, what UTXO they're talking about because there's no, you know, seven ninety nine Can mean a lot of different things in the con-- in the context of like two weeks in Bitcoin, that can be a very different amount. So it's very-- it, it takes a little bit more back and forth between them to figure out, okay, exactly what the issue is and, and to get the resolution. Now, there's one, one guy doing support on Samourai Wallet. And there's a lot of support requests that come in. So we need to figure out, okay, how do we, how do we maximize this guy's time the best? And the only way to do that is to reduce The, the, the issues that are coming in.

    and maybe it's drastic, but this is one way of reducing that issue. And it's worked because the, you know, the, w-w-one, we stopped with the silly sort of, "Hey, I, I sent, you know, two fifty, but now it says, you know, three seventy-five." You know, we stopped that almost completely. maybe there's just a few stragglers on old versions, but, Now the, the, the legitimate support requests, they take, less amount of time to complete. So I think, you know, that was successful. And, you know, the other metrics to-- that we, we were keeping a, a very close eye on are, well, what are the uninstalls and the installs? H-Has that been, i-im-impacted by this decision? and no, they haven't. You know, installs are actually, up and uninstalls are actually down since that point. So, you know, I don't think it's because of that that there, the installs are up, other than just the, the, the press perhaps that, you know, came, came around it. But, uninstalls being down is great, you know? so I think By every metric that we, we, conceive, it, it seems like, it was a good decision. Our users are, are, staying around and new users are joining every day. So I think it was a good move.

    Yeah, great to see. Okay, let's talk about Paynims, Pip47. Now, earlier you mentioned about the problem of people putting up addresses on their, say, on their social media account, and now that is forever tied. Tell us a little bit about Paynims and how that can help.

    Yeah, well, that, that's like one of the, the perfect use cases for Paynims. It's the, the, the public donation address problem. Like you wanna receive donations, from the public in a, in like, you know, in the, in a very simple way, that's what Bitcoin has, has promised, right? Here, here's a QR code, send me some BTC, you don't have to ask me for anything, I don't want, you know, everything is, is good. Well, the issue with that is you're, you know, publicly associating an, an, an identity, whether it's your life, your true life identity or it's some other sort of, digital identity, you're still linking that to that particular address. and, and anyone who, who sends to it is linking themselves, if they've made their addresses known, to, to you. this is, this is a privacy problem, especially considering when you consider the fact that The, the, the blockchain's immutable and this can go back, and people can look through this for, posterity forever. this becomes a privacy problem, and BIP 47 allows you, or solves this problem by allowing you to share a, a static code that doesn't change. but has the, has the ability to, allow users to send b- Bitcoin to that, that, that code, let's say for simplicity's sake. Without revealing the balance for one of the, of the donations address or the transaction history. So what ends up happening is a unique, what we call a stealth address is generated between the sender and the owner of the code. Of the payment code. And, e-each person who sends is gonna have different addresses generated based on, you know, their own, their own wallet. So, it's a very, it's a very nice solution to the static address problem. It's, it's, it's similar, in what it achieves to what Dark Wallet did with, stealth, stealth addresses. with the ex-the difference being it doesn't rely on a server, it just relies on the, on the blockchain, to, to achieve that, that goal.

    Yeah, fantastic. Okay. And so then really the only downside is just that you would have to, you wouldn't be able to instantly send a payment through, you would have to open a kind of a payment channel with that person and then send through the shared

    secret. That's, yeah, that's a pretty big downside. It's actually, you know, I would, I would classify it as a major downside for, for a couple reasons actually. The, the first reason is it's a UX disaster. You know, like, okay, now I have to wait for a blockchain confirmation. by, by the time you do that, unless you're really dedicated, you're not sending that donation, let's be, let's be honest, you know? So That, that, that, that alone needs, needs, needs to be solved. But, but also, I, I believe that, Luke Junior, Luke Dash Junior brought this up when, when Justice Ramveer, when Justice Ramveer, introduced the BIP for, for, reusable payment codes, is that really the The notification transaction is kind of unnecessary, and it, and I, I think Luke put it as he, he, he saw it as spamming the blockchain. I, I wouldn't go that far, I, I disagree with that, but I, I do think it is maybe a bit unnecessary. I understand why the notification transaction exists, and in, in fact, it exists, because As I, I just finished saying, doesn't require a server, it requires the blockchain, when you, when you restore, especially from Monomic, in order for your wallet to be able to determine You know, the addresses it needs to generate, these stealth addresses it needs to generate, it needs to figure out, well, who connected to me? And it does so through those notification transactions. however, we've been working on, on solving that problem. and we're gonna, we, we have a, a directory of payment codes called Paynim dot is, and I think within the, you know, in the next, definitely next year sometime, there's gonna be a, an opt-in Paynim dot is sort of bridge, so that users who wanna do an instant payment would be able to do so in a, in a private manner, without, you know, without sacrificing any privacy. With different trade-offs, and the trade-off being the ex-uh, the restoring from blockchain versus restoring from a encrypted, you know, payload on a server or something like that, of, of which payment code's connected to which payment co- to, to you or vice versa. So there, there's different, there's different trade-offs in solving that problem. again, that's more of like the, like I said, the stealth address model. so w-we'll see what users opt into. That really is what it comes into, down to at the end of the day. okay.

    Yeah, cool. Nice. alright, let's talk about Ricochet. Now, I thought this was an interesting feature as well, so I was reading about this and, may-actually maybe you can tell, give the audience just a quick overview on what it is and, you know, how effective it is, that kind of thing. Sure.

    Yeah. Well, so, so Ricochet, we got the idea of Ricochet from a, a talk, at a conference that Adam back and, and, Matt Corallo did, where they, he mentioned that the blockchain analysis companies were, were looking back at, usually at most around four to five We'll call them hops, backwards of a transaction's history, and determining whether anything fishy happened within those, those hops. well, I mean, really, if you think about that, that's, that's madness. Five, five transactions ago can be anyone, you know? Like that, that, the associating that to the person who's, who's sending now is, is kind of, a reach. so, so we had the idea, and it's a very simple idea, of, of ricochet, which is, okay, well, let's just add hops of history before the transaction reaches its final destination, because it's not like this is some sort of sophisticated thing they're doing. They're just looking back five and seeing if, you know, any of those UTXOs or that transaction matches anything on their, their blacklist. And if it doesn't, alright, it gets passed on through. It's like the, I don't know, a, a customs check, you know, a really, unmotivated, customs official. Yeah, yeah, go on, go on, you know, that sort of thing. They're, they're doing it, they're doing, they're get, they're doing their duty, right? But are they really? So we said, well, we can, we can easily thwart this. This is easy to, to thwart. So we did, we, we created

    and we launched that, a little, more than a year ago, and we've had a lot of users, a lot of usage on it, and we've never had a complaint, we've never had someone say that they've, their account got shut down or anything like that. So it appears to be working, it appears to be effective. A lot of repeat, users, at, at least that's what people tell us. So I think it's a, it's a cool feature, and it also, it also, it's a premium feature, you know, users pay for this feature, which, is honestly one of the ways that we keep, we keep going, we keep running, it's able to at least pay for the, server bills, right, for our node and stuff. So it's, it's an important feature for us, but it's also, I think, an important feature for the ecosystem. And, it's also really important to understand, in order for the chain analysis people to combat this, they need to increase their costs, right? Because think about it, they're checking the, the last five hops of every transaction that's coming into this platform. So we're not talking like, you know, a couple, a couple hundred, a couple thousand, we're talking on these big platforms, twenty, thirty million with twenty, thirty million users. Think about, think about that, right? Now, so you got it down to, okay, you're doing four or five hops on these and that's working good. What you're gonna start Start extending that to seven, eight, nine, ten hops. Not only is that gonna cost you more money and, and just raw processing power, that's gonna cost you lost revenue in terms of your user base either getting incredibly fed up by these false positives that are being thrown out and going to your competitor. Well, yeah, I mean, it's, it's really as it comes down to the economics of things. So I think, that's, that's probably the reason why we haven't seen any real response from, from the exchanges or anything like that to Ricochet. they haven't increased their hops, it doesn't appear. probably because why would they? Like, it, it's not, you know, okay, this is good enough, it passes muster, five transactions and it's good. Yeah.

    And like you said, it would be very-- because then they might start actually pinging innocent, you know, from their own point of view, they might start-- Although they already will

    be, yeah. Yeah. Yeah. I mean, if you're going five hops back, I mean, you're already gonna be getting innocent people without question. That's a lot of transaction history.

    Yeah. And I like the other thing, the point you were making is that whole asymmetry around the cost to kind of implement this kind of defense versus the cost of a blockchain attacker to try and attack, like the computational cost on their side is much higher than, you know, the defensive cost. Yeah, it's just

    changing a variable for us. a-and that, and that's not even, I didn't even mention that we have planned improvements for Rikoché. we're testing right now Right now, a ricochet that goes, adds transaction history within lock time between different, between different, blocks, right? So you can start on, on, you can start your ricochet on this block today, right now, and then the next hop will be The, the next block or two blocks from now, the final block, you know, so by the time your transaction actually reaches its destination, it could be like twenty-five blocks from when it started, that ricochet. that just breaks the, the ricochet fingerprint almost completely, detecting that on their end. So this is like think, us thinking adversaryially now. This is like us thinking, okay, what if they start to attack ricochet? What if they say, okay, we're gonna fingerprint all these ricochets and, and, you know, now we're gonna come down Extra hard on these people. That's how we're thinking. So this multi-block ricochet would, would be a very strong solution to that.

    Yeah, right. And as you say, it's, it's like, people use that expression in security that it's like a cat and mouse game, that you constantly, you try, you, you know, one side goes up one, and then the other side tries to go up even further, and you know, yeah. Now, actually, that's an interesting point I wanted to ask as well, is just around, you know, heard immunity. Is there such a similar concept in Bitcoin that if enough people use these kinds of privacy preser-preserving features such as CoinJoin and Ricochet and Stonewall, that, you know, even users who don't use those features get protected?

    Yes. Yeah, absolutely. I think, I think Adam, Gosh, he, he wrote a Medium article about, about this, I, I, the title's escaping me, but it was really good and it's basically, oh no, privacy is teamwork. Is the, is the article of, Adams and Fiscor, I mean. And it, it's, and, and it, it's absolutely true. And, and, it's about incentivizing the people to use it. And it's about, you know, realizing that this isn't about protecting criminals, this isn't about trying to help people launder money or anything like that, if you even subscribe to that concept. this is, this isn't about that. This is about fundamental rights and, and the, the, the right to privacy in, in, in, in transactions, I think is, is not something that's negotiable. And it's something for everyone. It, it, it's as fundamental as, as the right, as freedom of speech. In fact, it is freedom, it, it's part of speech. You know, how you transact is, is, is tantamount to speech. So, you know, it, it's just not negotiable. and I think, and I would love, you know, obviously protocol level privacy improvements, I think that'd be a huge step, right? to, to getting that, that default position. But until that time, On building tools that are gonna hit, you know, are gonna reach a large portion of the market, even people who maybe wouldn't even subscribe to those tools, just like, like WhatsApp, you know, with their encryption probably very imperfect, but it, it brought that encryption to the, to the masses. and brought even just the word encryption to them, because it gives you, gives you a nice little notice when you, when you have, WhatsApp in there. so, so that, I mean, that's, that's the sort of kind of shift I'm talking about. You need that, and that's not something that Samurai Wallet can do alone. You know, that's, that's a, that's a concerted effort type of thing.

    Yeah, yeah. And one thing you pointed out earlier is just around the incentive as well. So if there's one pathway that costs money and another pathway that is not so costly, well, people might take that path. actually, while we're on that topic, a related feature is stonewall. So my understanding is that is a feature that is implemented by default in the wallet. Can you tell us a little bit about that? Oh yeah, sure. So,

    Stonewall essentially, well, it creates transactions that are mathematically indistinguishable from a CoinJoin transaction. a-and by, by extension, visually, indistinguishable. So it looks like, it looks like a transaction, that multiple participants have, have joined together to create, a standard mix transaction. It would look like a transaction from, from Wasabi, for example, from sort of from Join Market, et cetera. However, it's not, it's, it's, it's just your wallet. It's a decoy. It's fake. It's fake coin join. however, this ties into what we were talking about earlier about breaking these assumptions and breaking the heuristics that these analysis firms use. mathematically, they can't determine, with any certainty that That the inputs in a stonewalled transaction belong together, belong to the same wallet, and likewise they can't determine which of the outputs was change and which wasn't with any, any degree of certainty.

    Right, I see. And I, and my understanding then is that the wallet kinda does some clever coin selection to craft the transaction in such a way. So is there a method to do like manual coin selection in Samourai or is it more just like it automatically does it? so- So,

    yeah, so coin selection's a huge topic, huge, huge topic.

    by default, like you said, Stonewall coin selection is the algorithm that's, that's used, and, We can, we can give your listeners a, a link to a, a GitHub gist of, of a breakdown of the algorithm by Samurai Dev. but, but essentially Essentially, UTXOs are grouped and put into these randomized, sets based on the address type, so whether they're, P2PKH or, P2P or P2WPKH or whatever they are, they're put into random, in sets and are processed in randomized order. so, so because of these conditions, not every transaction can be a stonewall transaction. And the wallet will alert you when a stonewall transaction cannot be composed. it's sort of the more you use the wallet, the more likely it will, activate

    if, if the, you know, Stonewall can't activate, there's other coin selection, rules that, that are applied in Samourai Wallet, and I, I would think most, most, good wallets, merge avoidance. So if, if, if UTXOs have been seen together, in, in a previous transaction Don't, don't use them again. or don't use them in, in a transaction together again. so that's, that's a simple kind of, selection technique to just, to avoid that merge, avoid, that merging inputs issue. again, if you're doing a full wallet spend, you know, the, you really can't get around mer- merging inputs, but the wallet again will warn you and say, "Hey, you're gonna merge these inputs, are you sure you wanna do that?"

    Yeah, that's clever,

    I was reading on your blog that one of the ways that you analyze these transactions is by using what's called Boltzmann scoring. do you wanna just give the audience just a, a brief overview of what that is and how that works? Yeah, well, I was, I was, I

    was just gonna get there actually, because it does tie in, you know, it ties into coin selection. To date, most of the academic papers and most of the research on UTXO selection has been, largely around amount and age. So what we're doing is taking that a step further, and this is how Boltzmann ties into that, where Boltzmann looks at a little bit more than just, amount and age of a UTXO, it's act-- it's also looking at, what's called its, entropy and/or, and also its wallet efficiency and, Of a transaction, right? So, the entropy of a transaction you can think of as the, number, of combinations between that, that can be, that are, that are mathematically possible between inputs, the outputs. And how many different ways can you break this transaction down and say, "This, this input is to this output, or this output is to this input, et cetera." And the, the second one is wallet efficiency, which is the number of deterministic links, and that's saying, okay, well, we can deterministically say that this input is, is put to this output, and there's very complicated math behind this, and luckily, Laurent, who, who runs OXT. has a very strong mathematical, interest, and he's the one who put these tools together. So, so what we're able to do is leverage these tools, Like Boltzmann to, to select UTXOs that, maximize privacy for the, for the end user. So this hasn't, this hasn't necessarily been rolled out yet, where this stuff is still in testing, but, so UTXO selection is something that we're, we're really focusing on in a, in a research and development capacity. The, the one, the one kind of quirky feature that we do have, just jumping back to coin, coin selection or coin control, at least on the user's end. so we will have the ability to, to have finer-grained coin control in the wallet in the future, saying, "I wanna actually spend from these particular UTXOs in my wallet," and, and, alert the user if they're doing something kinda dumb. But right now, what you can do in the wallet is mark a UTXO as unspendable, so you can kind of reverse coin control yourself, right? You can say, "I don't wanna spend this one, and I don't wanna spend this one." So you kind of force the wallet into, into a situation. that, that, that can actually be, be useful, for a number of reasons, but we implemented that, that functionality, to protect another, against another type of privacy invasion, which doesn't happen that much anymore, but was kind of popular two or three years ago, which is a, a, a dusting attack. So a small amount of, of Bitcoin is sent to your wallet, it's usually the dust limit, and, You know, oh yay, great, free Bitcoin. but then you spend that Bitcoin and it, it, it usually has to be merged into a transaction. With other, you know, other inputs because it's such a small amount, and then, yeah, then they gotcha, right? Now they, now they have a chain, and that's, that's, that's another way of that starting, attack, right? you, you didn't, maybe didn't even, you didn't, You, you somehow put this address somewhere that they, that they were able to put it, or they just kind of generated, ran, you know, a Bitcoin address and sent to them? Various different methods, but you, you know, you may have done nothing wrong, but now you're in their scope, right? Now you're trapped. So with Samourai Wallet, you can, mark that as "Do Not Spend," and your wallet will never spend that thing. The true huddle is option. Well, that's the other thing, yeah. We've had people who have said to us, "Yeah, you know, this is great. I, I, I mark half of my wallet as "Do Not Spend," I forget that I even have it there because So some people have said it's like finding like a, a twenty dollar bill in your back pocket, you know?

    Well, it's a new age and we need a new analogy, a new, it's almost like a Trojan horse attack. And, and here's the other thing actually, that, it means anyone who's using a public donation address is kind of vulnerable to this attack if you, if they, if someone sends you dust, whereas if you use paynims, then that, that attack is now obviously a lot less viable. No, that's right. Yeah,

    yeah.

    So now the next thing I wanted to talk about, and I've seen, one of your fellow samurai, you know, wallet partners, T Dev, yeah, samurai dev, he wrote, yep, he wrote about stowaway, which is, I think it's a new feature you guys are working on, and, in the wording, T Dev said it was "Neither output displays the true spend amount, which is in effect stowed away via a trusted cooperation between two wallets." Do you wanna tell us a little

    This is a unique transaction type, that's gonna be available, a-after a user has whirlpooled their, their funds. and this is a, what we call a post-mix transaction. One of the, you know, we, we can't forget that you have to spend your mixed BTC at some point, or you don't have to, but many people will. and that can undermine your privacy quite a bit, if, if not handled with care. So a, a, a post mix transaction A stowaway will be one of, one of three post-mix transactions, so transactions out of the mix.

    And The, the stowaway has, has the asterisk that this is between samurai wallet users, presumably because it requires a, a pay-in. So, as of now, it's, it's samurai wallet and, and a few other wallets out there that even support BIP 47. So, you know, it, it, it, it's requires a Paymem and it requires a Paymem, that You have some level of

    trust

    with.

    Right. And, and doesn't mean they could steal your coins or does it just mean they might help de-anonymize? So they'll, they,

    they definitely can't steal your coins, or have, or even have access to, to know what your balance is or anything like that. the, the type, the way the transaction works is You're essentially, sen- you're sending to them, right? I wanna send you, one, one Bitcoin, and I have one, UTXO of two Bitcoins, let's say. Right, so my, my transaction, if it was just a normal transaction, it would be on the input side, two bitcoins, on the output side to you would be one bitcoin, and there would be a change, output back to myself for one bitcoin. Right? That would be the, the standard transaction. Now, when we apply the stowaway, transaction to it, so the, the input is two still from me, however You, the trusted part comes into play where I say to you, who I'm sending to, I say,

    give me another UTXO in your wallet. Don't send it to me, but give me this information. So the trust comes in where I say I can look at that one UTXO. And in this case, you have one UTXO of two Bitcoin as well. So the, the, we use that UTXO of two Bitcoin that you also have. So your transaction now has an input of two from me, an input of two from yourself, an output of, of, of three. To you, and an output of one back to me.

    very nice.

    Right, so, so- Yeah, that's pretty cool. Yes, and so again, it's, it's very specific. Stowaways are very specific. It's like, I need to send to one of my trusted contacts. Right? because, again, trust it only because they're gonna, they're gonna be exposing this UTXO that they have.

    So you need, you need to know who you wanna send to, essentially. and they need to participate in the send, if that makes sense. It's, it's, it's complex and, it's not even, we didn't come up with this, and we don't wanna take credit for this, because this is even, this is just too cool. this was, this, Greg Maxwell came up with this years ago. We just unearthed it on the Bitcoin Talk, message boards. And it didn't go anywhere. I, I think he, he composed one of these by hand, one of these transactions by hand, you know, people on the message board. We're contributing UTXOs to, to be used, for example. and that-- but it kind of ended there. So we found that and said, "Wow, this is a really interesting transaction type. It's essentially a mini coin join, 'cause you, you're, you're, you're collaborating with one other person. You're not doing a larger coin join with multiple participants. You're doing a one, one person or a two-person, you know, transaction." But it's essentially a, a very small coin join. so we were excited about that, and we thought it'd be a very nice post mix, method to leave the mixing wallet. And if, thinking abstractly about it, what it's doing, it's not just, oh, this is a neat kind of, you know, trick. What it's doing is, it's again attacking those assumptions. It looks like a very normal Bitcoin transaction, very standard. However, it's not. Both those inputs aren't owned by the same wallet, you know, you can't connect those. So that looks like your "bog standard transaction" and it's a mini coinjoin. So the, the assumptions that a lot of these blockchain analysis firms are gonna, are making are now gonna just be dead wrong.

    Yeah. It's a very clever idea. And with the coin join idea, you sort of have to wait for a round, and that might be take, that might take time, whereas in this method, it's just you and one other person. Yeah.

    Yeah, so yeah, the coin join, you may have to wait for a round. w- we don't expect, we'll have to wait around all that long. it's kind Mobile. you'll have a, a fairly large user base that doesn't really have to do anything. They don't have to install anything, they don't have to compile anything, they don't have to do, do much, you know, so the barrier to entry is a lot lower. and the, one of the, one of the differences between, Zero Link and, as just as a, framework and Whirlpool as a product is that Whirlpool is adding on a incentivization layer, So we expect that liquidity will be, it will be deep and, and, rounds will be very, will be lightning quick.

    Right. Okay.

    What's the incentivization layer? we're, we're not, not a hundred percent ready to, to go into it, but, but, but I will say it's been, it's been, inspired by, Join Market, which I've always admired. especially the, the economics of the incentivization, I think it's very, very clever. I think they, they had, the same issue that I was just talking, talking about, where it's just a barrier to entry to use it, to using that product. So, so it's inspired by that, not, not exactly the same, a maker-taker model kind of idea, but, we, we think that, I think we think it's gonna be pretty, pretty awesome, and I can't wait to really kind

    of, Trusted node. Now, there has been a little bit of debate on Twitter. There were a few people making comments. I think Luke JR and David Harding, were commenting that apparently the trusted node is potentially exposing users to some more risk if they don't execute it correctly because the method in, you know, in, involves exposing their RPC port to the internet. Do you have any comments on that or maybe what is the correct recommended way to use this? Yeah,

    sure. You know, I, for one, I think I think it's important To say that it's very, very difficult to have any sort of meaningful debate or, or not even debate, but conversation of important things like this on Twitter? So I think it would have been a lot better, to be handled either on GitHub or on, on email, or something along those lines. So, it, it just made it much more difficult to to keep track of, of the thread, and all the divergences of the thread, and also to combat the frankly, misinformed or, Mistold information that was going around. it makes it very difficult for, for us to be able to, to counter that. So hopefully in the future we'll be able to, to take that sort of stuff to GitHub.

    That being said, I, I, I think, I, I think that,

    the, the RPC, method of connecting to the user's full node While imperfect isn't a gaping security hole, I think Luke probably means that in the same way that he means, you know, the tonal number system will be easier for the common man. and I don't mean that with disrespect, 'cause I respect Luke, a lot, but I, I, I think he meant that in the same kind of way.

    It's, you know, I personally disagreed when Bitcoin Core removed, S- well, not SSL, but they rem- they removed SSL, in zero dot twelve. because of, well, SSL is a nightmare. However, they should have replaced it with TLS, in my view, and that would have, that would have maintained the encrypted state of the RPC. So, BTCd does this by default, and, Most, you know, most RPC, methods also, do SSL or TLS, so I, I don't think it's, it's entirely fair to, to blame us for users doing silly things. to bypass, you know, stuff that, has been, has been made on the node level. the, the, the suggestion is to do SSH tunneling, but it's, that's not very easy to do on a, on a mobile device. and at the time there was, the Tor option wasn't really available to us. So, you know, the, in the context of when we launched Trusted Node around the UASF, event, I think it was very important, and it still remains important for users who are running their own node. one of the things Luke said was that it, it isn't effective. That is not true. It is effective. It does exactly what it's described to do. it does broadcast your transactions from your personal node. Not from some a node, where you control the consensus rules. it, it, d- it gets the proof of work headers from your node and compares them to our node, and if there is a divergence, it alerts you and warns you, says something isn't right. This was, this was implemented, at the advice of Peter Todd, who, suggested it on Reddit. And also was very important in the context of UASF, if our nodes lied to you, you know, we were very supportive of the user activated soft fork, and we said that, we, we warned users that our nodes would be following the user activated soft fork in the case of that split. However, we could have been lying, and users were trusting us, and we've been very open and honest about our architecture that you still rely on Samurai Wallet, you still trust Samurai Wallet to give you right information That's one of the reasons why we're alpha. You have to trust us for that, and we're working very hard on making that not the case, but until that, you know, that's released, it is the case. Sure, sure. so, so in order, in order to combat that around this very contentious time of user activated software, we said, "Well, if a user is expecting, to be following user activated software and they're running their own full node and they're broadcasting via their own full node," and their full node then report, or, or, or their samurai wallet then alerts them that says, "Hey, your full node and our node has a different proof of work header." You know something's wrong now. You know, so that was, that was the idea around that, and that is working, that's, that's not ineffective. and then the last, the last thing it does right now is, get the, the fees from the mempool, from your local mempool. on your node. So that's what it does right now, and we've always been open that there's plenty more, planned for trusted node, the, the, the ideal, end state of trusted node. Is bypassing Samurai's infrastructure entirely. and, and by, by, you know, the next step that we have to do to, to help make that possible, I mean, we are Well, we're like weeks away from that. This has just been kind of bad timing for us, but I mean, we're very close on that feature. So, on the one hand, it was, it was unfortunate to have to deal with that. And kind of the anger of it on that day, but I'm, I'm not too worried about it because I know what we have in the pipeline and, most of, all of the issues that were, were, were raised have already been resolved, they just haven't been rolled out yet.

    Okay, sure. Okay, well, I guess we'll look out for the, the update coming in a couple weeks then. alright, not in a couple weeks.

    yeah, i-i-it's coming, but- I can't give a hundred percent timeline yet. I would say, sure, month is, is probably better. Okay, sure.

    Alright. now the other thing that's really exciting that a lot of people have been talking about is this TX Tenna or Gotenna collaboration. Do you wanna just tell us a little bit about that?

    Oh yes, that was, that was fun, that was a cool project to work on with the Gotenna guys. So w-we launched, MuleTools a little while ago, which is, is one of our research and development initiatives around censorship resistance. So all sorts of different ways of broadcasting transactions and getting block data and without using the internet. So Gotenna stumbled across this. I think, I think Richard Meyers, who, who's a, a decentralized app engineer or something over there, he, he, he came across it and he reached out to us and like made all the connections happen. and we, we met up with Gotenna and they, they showed interest in, in bringing, Bitcoin to their users and to bringing Gotenna to our users. and we thought it was a really cool, project that fell in line with the Mule Tools initiative, so we, we conceived of a way to, expand our current, Proof of concept app that we had at the time called Pony Direct, and what Pony Direct did was broadcast transactions via SMS network. pretty handy if you're outside of like 3G, if you're on edge or something, or, or worse, or, you know, We decided, okay, let's extend that and make it SMS based or GoTenna mesh network based if you have a, a GoTenna and you're in a, in an area that's nicely connected. so that, that's kind of what we ended up working on, and, it kind of, it, you know, it followed the same ideas of the SMS-based, solution, used kind of the same, you know, the same architecture, breaking up the transaction into segments.

    w-in its own sort of payload format so that they could be reassembled, later on. And all of that's open source. the app came out, at the HCPP conference in Prague And, yeah, it's, it's, it's fun, it's cool.

    Fantastic. Yeah, I thought that was really cool. I saw, there was a guy, I can't remember his name, it might have been Co-Insure or CoinSure, New Zealand. Yeah, so I think he did one where he paired up, a bunch of, Gotennas a-along a route, and I'm not sure if he used Samurai Wallet, I think he did, to then actually do a Bitcoin transaction on it as well, which was really cool. So

    yeah, I think he has like the distance record, I think, now. It was very, very long distance.

    Yeah, so, as Safteen said, it, it, you've got to, en-envision an even more crazy scenario for Bitcoin to get

    Is, is coming every day. I saw, I saw something go by which is broadcasting, you know, transactions over, with Morse code over radio, now, and that's-- there's some working code on that in, we forked it in the MuleTools repository, but I think that was, Matoshi on Twitter who did that one. So that's pretty neat. And, yeah, a lot of people are inspired and a lot of people, should be inspired and, and these sorts of tools, you know, while they may seem like kind of novelties right now, may become extremely important and maybe already are extremely important.

    Yeah, depending where you live. Yeah. and, and then the other thing now, I, I noticed, speaking of New Zealand, they passed a law recently saying, I, I can't remember the exact wording, but it was something like, "If you don't,

    Password for the agents when you're trying to, you know, come into the airport, they can fine you or they can put you in jail. so that, you know, brings up this idea of being able to, you know, hide your wallet, have stealth mode and remote commands.

    Yeah, yeah. it's definitely a use case, you can definitely do it. It, it wouldn't, it wouldn't hold up, I mean, I'm gonna be honest, it wouldn't hold up to any real scrutiny of the device if, If you unlocked your device and gave it to, you know, border security or whoever was examining it, and they took it away for long enough, they would be able to find your wallet if you had it in hidden mode, and then you may be liable for all sorts of other criminal charges.

    Yeah, right.

    My recommendation, and I've been, I've thought about this a lot, is to, just, well, you know, for Samourai Wallet, what a user could do If they've noted down their mnemonic and, and their passphrase, it's just simply uninstall the wallet and then reinstall it when they're over the border and restore it. Like that, that's, that's the, the, I think the most legal way of, of doing it. Right? Because then you're not deceiving anyone and, and you're not, trying to skirt any sort of laws or anything like that. Right. Right. Okay. If, if the, the idea of stealth mode, and it, it is very useful in casual examinations. So someone is perusing your phone for whatever reason, there's nothing on the, the home screen, there's certainly nothing in the, the launcher. in order to activate it, you have to dial a special code. However, if, if they started drilling down into the- Settings, for example, and drilling down into the app permissions, they, they would see it in there. So if they knew what they were looking for, they'd be able to find it. So I don't want to give anyone any false impressions of that, but for a casual someone at the bar who picks up your phone and looks through it for a Bitcoin wallet or, you know, banking apps or anything like that, they're not gonna find it.

    Yeah, and that's a good, way to help, keep that hidden a little bit at least. Yeah. Okay, Home, you know, there's talk about confidential transactions. Do you have any thoughts on that or, actually, also on the topic of confidential transactions, do you have any thoughts on this whole idea of perfect binding versus perfect hiding?

    the only, the only thing I can say about confidential transactions is, I, you know, we, we wanna see it Live on, on mainnet, we wanna see it on the platform. I, I, I've said it before in other, in other interviews, I, I'm skeptical that we would ever see that on a protocol level, just because of the implications of it. I hope I'm wrong. We're, it's kind of a, a wait and see on that, but, as into the intricacies or, no, I don't have any, any sort of, opinions on that right now.

    Sure, sure. And then how about any of the other, you know Factories, any thoughts on those? yeah, we're very, we're very

    excited for Schnoor, I think that, that would, that, creates a huge, amount of innovation or unleashes a huge amount of innovation that's kind of waiting on, on that. So Schnoor would be huge. we're, excited for Dandelion, we'd like that pretty much as soon as possible. I'm not, I'm not familiar with the channel factories, off the top of my head, I'd have to look

    into And Lightning wallets. So do you think of it like all Bitcoin wallets will eventually incorporate Lightning, or do you think it's more like they serve different roles? So for example, I know you have another product which is called the Sentinel, which allows a user to basically put in their xPub and use it like a watching wallet. So do you see it, do you see it like people might have a, a Sentinel or a Bitcoin style wallet and then a Lightning for day-to-day spend? And what would that look like in practice? Would users just walk around with two wallets on their phone? That's a good

    And I, I think it's, I think one thing that we can be certain of is that users won't have any problem running more than one Bitcoin app on their phone, more than one Bitcoin wallet on their phone. I think many users do that already, and even outside of Bitcoin, you see many users running three or four chat apps at the same time. exactly. You know, so I, I, that I'm not, that, I think is a given. I think the, what's gonna end up happening is you're gonna have specialization and you will have lightning specific wallets and you will have main chain wallets. I think that's probably for the best. As specialization is good. but maybe, you know, no, obviously we'll have, differences to that approach and you'll have outliers, and, and I guess we're just gonna see what, what, what comes of that. But, yeah, a lot, a lot has to be, d-d-seen with Lightning. And it's, I, I, you know, we're excited for Lightning, as a technology, and I think it's important that the infrastructure is being built out now I don't, I don't see Lightning as a, as one of the "build it and they will come" sort of things. I don't think it works that way with, with Bitcoin. I think it's, it's a matter of- Build it so when they come, it's ready. And I'm, I'm, I think that's, that's a very positive development in this space that's being done. The infrastructure is being built out. in such a way that I think when, when it's needed, it will be ready.

    Yeah, right. That's, I think that's a good way to think about it. okay, so- What about censorship resistance? So there are some recent examples of people getting shut down, for example, you know, famously Alex Jones has been kicked off a lot of social media. Do you think it's likely that Samurai Wallet could eventually get kicked off Google Play Store or off Apple Store? And do you have any ideas on what to do in that case?

    Yeah, I mean, it's definitely something we've thought about, It'd be crazy if we didn't think about that. right now we rely on Google Play for distribution. It's the only distribution method we have, and that's entirely only to, Because it's an alpha build, restrict the number of APKs that are going out, out there. We wanna make sure people are updating quickly and getting all the bug fixes that need to be, you know, they need to have. so it's, right now it's kind of, if Google Play was to say, "Hey, you're out," then we would be, we would, we'd be kind of in trouble. We have, contingencies, of course, there's no, there's no reason why we couldn't go onto F-Droid APKs, third party, other third party app store APKs, all of those are open to us, and we intend a hundred percent to do both, self download APKs and F-Droid for the one point o release, So, you know, I think once we do that, once one point o comes around, then we have now multiple methods of, of getting the product. I, I- I don't think it's that big of a deal. I remember in before, before Google Play allowed, wagering and gambling apps in the Play Store which is a regulated and legal activity in, in many countries. Those, those, those, companies, they still had mobile apps, and they still distributed those apps to their customers, and millions and millions of their customers use those apps. So, you know, I think if they were able to crack that distribution problem, We, we certainly will be able to take some cues from that, and I think if people want it, they'll get it, you know? And it, it maybe even, maybe it, it would even add to the, you know, publicity around Samurai, these bad boys that got kicked out, you know? Where can I find them?

    Maybe, maybe it'll be like a barbershop. But,

    that being said, I really hope it doesn't. we, we, we review the Play Store terms of services as often as they change to make Any rules. and we work with Google as well. We have a, a, liaison with Google, who we can just say, "Hey, we wanna do this. Is this okay?" And they can say, "You know, that's, that would probably break terms of service, or you shouldn't do that. " So Google, it's been really, really easy to work with, Apple's a kind of a different story. and we're gonna, we're gonna e-e-edge on the side of extreme caution with Apple, 'cause, you know, getting onto the iOS store is, is not only a, a large investment of time, but it's also kind of a large investment in money, and getting kicked out is kind of a permanent deal, so we don't want

    Yeah, speaking of, I've got to ask, I, I personally I'm an Android user, but, when iPhone version?

    Yeah, it's, it's being worked on now. Sentinel's, essentially days away from coming out on the iOS store.

    Samurai Wallet itself is being developed, so we're hoping in the new year, early new year.

    Okay, cool, cool. any other? I, I guess we've spoken about some of these features, but do you have any other features or releases coming up that you want, listeners to keep an eye out for? Oh, gosh, yeah, we kind of

    went through, I think, everything on the, on the, public side. I, you know, the, Trans-- the post-mix transaction types, those are kind of a big deal. Stowaway, I hope I did a good job explaining, that's kind of a complicated one to explain. yeah, no, I thought it was good. Okay. Ricochet, all that sort of stuff, being improved, trusted node being improved, being replaced by what we're calling Dojo. I don't think I said that before, so that's, that's just, that's a scoop. Very nice. And, you know, we're gonna combine that with a partnership

    so users will be able to have a true plug-and-play experience, with a full node pairing to their mobile wallet, via Tor hidden service. So I mean, like all, all this stuff is coming out, and we're a very small team, we're self-funded. We, our mission statement isn't, isn't that you, that you read at the beginning isn't BS. Not only did, did, you know, VC's not want to invest, they really couldn't. There is no structure or entity to invest into. and, you know, VCs don't like that generally.

    Yeah. So- Okay, well, on that topic, if someone wants to support you guys, how can they do it? You know, it's open source development, can they contribute Bitcoin? Can they, you know, use Rikoché? Yeah, yeah, all of the above.

    w-we're available on GitHub, you know, you can go through issues on there, you could submit pull requests, chat with us, you know, on Telegram and, and talk, talk out some

    using Rikoché, honestly, it's, it's the single biggest way you could, you could support us, and it, at least, monetarily, I mean. It, and it, just, just use it, you know, use it sparingly, use it when you're actually sending to an exchange. We met a guy at a conference, or a nice guy at a conference, who was telling us, "Yeah, I just, you know, I just used Rikoché to buy, buy this bottle of water." And I

    to Binance or Coinbase or something, you know? and donate, you can go onto samouraiwallet dot com slash donate, I think, and, we have a payment code on there, which, which is what you should use, but we also have a static address if you wanna send the old school way and, and taint yourself.

    Well, I hope you've marked that address as "Do Not Spend". Yes, yes,

    that address is "Do Not Spend".

    Okay. And, I suppose just last closing thoughts, do you have any advice for users on maintaining privacy generally, not just in Bitcoin?

    Maintaining privacy generally. yeah, you know, check out Lop's, Twitter feed and read his resources. I think that guy has a pretty, has a pretty good grasp on the outside Bitcoin, privacy methodologies.

    Excellent. Alright, well, I think, that's pretty much gonna do it for us. So, look, it's been a fantastic discussion. I think, it's been very educational. I've definitely learned a lot in terms of the ways, you know, the transactions can get constructed and various, you know, initiatives and projects that, you guys are doing. I think it's a pretty cool project. Thanks for coming on. Yeah, thanks a lot for having me. It was, it was great. So there you have it, my conversation with Samurai Wallet. on Bitcoin privacy, merge avoidance, coin selection, the state of currently available Bitcoin privacy technology such as Ricochet and Stonewall. I'm also quite excited to see some of the new features coming, such as improved Ricochet, Whirlpool, and Stowaway, and the Dojo trusted full node feature. For listeners who are new to my podcast, if you liked this episode, you will also like my earlier episode SLP twenty-four with Adam Fitchor of zkS Snacks. He is the cto of the company and lead developer of Wasabi Wallet, another privacy focused wallet project. Anyway, Samurai Wallet is available on Android, so go take a look. For my iPhone listeners, sorry, you'll have to wait a bit longer to try it. Lastly, please help me change the conversation from quote unquote crypto and scammy altcoins, ICOs, enterprise blockchain technology projects to Bitcoin by sharing this podcast with your friends, Facebook, LinkedIn, Twitter, Telegram groups, Discord, WhatsApp, whatever you're using. I also really appreciate any good reviews you can leave for my podcast, as that helps new people find my podcast. Come follow or DM me on Twitter at Stephan Livera. My DM The DMs are open and I respond to just about everyone. That's it from me. Speak to you guys next time.