NODE ONLINE
EP 563
slp@node:/transmissions$ open --transmission SLP563
TRANSMISSION_DETAIL

TRANSMISSION SLP563

Revault, Liana, self custody and bitcoin inheritance

with Kevin Loaec

DATE 12 April 2024
DURATION 01:14:52
GUEST Kevin Loaec

Kevin Loaec of wizardsardine joins me to talk about bitcoin security and vaults. We get into a discussion about:  • Vaults and what’s possible today  • Timelocking and using them as part of self custody • Inheritance scenarios • Business use cases • Covenant soft forks

listener@future:/timestamps$ list --chapters
CHAPTER_INDEX
listener@future:/transcript$ decode --transmission SLP563
TRANSCRIPT_BUFFER DECODED

Hi and welcome back to Stephan Livera podcast, a show brought to you by Swann dot com. Today my guest is Kevin Loaec, he is from Wizard Sardine, known for their products Revault and Liana. So today we're getting into some discussion about Bitcoin vaults, time locking, as well as using them as part of self custody and more advanced setups that are possible that will help in use cases such as inheritance or perhaps for business or perhaps making sure that your backups are more secure. secure. so we get into a range of these topics, we do get a little bit more technical, but of course, I try to make sure it's accessible for listeners. And of course, just a quick disclosure up front, I, along with the Bitcoin venture partners, did also invest into, at the time, Revault, and so we have a small equity stake in, in the company, just so you're aware up front. But I'm sure there's lots of, interesting information for listeners out there in terms of Bitcoin. Bitcoin self custody and what direction it's going to go in the future. So here's my chat with Kevin.

Kevin, welcome to the show. Thanks for having me. So Kevin, you are the founder of Wizard Sardine and, the, so I guess the company's Wizard Sardine, but some of the products are Revault and Liana. And just for listeners, so you're aware, we at Bitcoin Ventures did do a small round, of investment as well, just so listeners are aware. I've, you know, put in a small, very small amount into this company, but just so everyone's aware. But, Kevin, do you want to just, tell us a little bit about what you What's Revolt and what's Liana?

Okay, cool. So yeah, Wizard Sardin is the company, we see ourselves as like a Bitcoin security company, so we really focus on all aspects of, of Bitcoin security, also in term of like contributing to Bitcoin Core, to, you know, finding some bugs and, and, and having a responsible disclosure, to other open source protocols, and when we find some bugs or whatever in, in proprietary hardware or software, we'll, so we also, go through That route, and we do a little bit, like just a tiny bit of, of kind of, security consulting, mostly like security audits of other open source, protocol and products on Bitcoin. So that's also one thing that's, that is not really common, in the Bitcoin space. It's pretty hard to find people to review your code, and so when it's, you know, very close to script, to the layer one, we can help with that. But, yeah, as you were saying,

Revolt and, and Liana. the company started kind of only with Revolt, so that's why people know it as like Revolt, the company. it didn't really make sense to communicate as Wizard Sardine when we just had one product, Revolt, so we were just, you know, calling it Revolt. and, yeah, Revolt is or was, the kind of the, the first and, and maybe only, practical Bitcoin vault, architecture that you can actually use right now on Bitcoin Bitcoin. And, as a side note, actually one of, like maybe our primary philosophy is that what we're building is with the Bitcoin we have today. So you will see that a lot with what we are doing, and same with Liana and, and potential future products, is that there is trade-offs. It's not perfect, but what we're doing works today on Bitcoin. We're not talking about what can be done. We're actually building what we can do with what we have today. And then of course, if in the future there is changes in Bitcoin Coin, maybe covenants and things like that, then of course we will improve our product with these new things. But for us, it's very, very important not to be stuck as a product company into potential things that, let's say, covenants that would, basically kill our company if it doesn't, happen on Bitcoin. And so, yeah, Revault being a, a vault architecture is very interesting because, up until basically Revault, it was believed, or accepted Accepted even that vaults wouldn't be doable without covenants, and there was a lot of discussions, right? We didn't invent, Bitcoin vaults, they were discussed since like two thousand thirteen, and so there was a lot of research on them, and, and mostly the, the point was that you can't do it without covenants. And, and when we started it, people were telling us, "You guys are crazy, why are you trying to do something so complex?" Because the extra complexity is required to make it work,

with In six months, we're gonna have up CTV, and I was like, "Yeah, I'm not so sure about that. I mean, I would love that, but I'm not gonna take this bet, and we're gonna go with what we have today, if CTV or whatever." So sorry, can we just

one thing before we get into this, let's just explain, just to, we're gonna keep it accessible for people, 'cause we're talking about vaults. Let's just, I'm gonna explain my, let's call it my ADIQ grug

Like, Brian Bishop and others, they kind of had this idea of what if you could secure your coins with a vault? And the idea is you can like have kind of a primary setup and have this kind of secondary backup setup. And the idea is you would have this primary setup where if somebody tried to spend out of that, you would have like a watchtower sort of function that watches those coins, and if they're being sent to an address that's not approved, you can kind of joint them or kind of yeet them out of there and put them into the secondary setup. That's kind of the kind of the basic idea of the vault. Now there are different constructions and different ways people spoke about doing this. There's like the precomputed vault, and that is sort of I guess that's kind of the level we're at today, and hopefully maybe someday in the future with some kind of covenant, Soft Vault or Op Vault or something, maybe you could enable more advanced features, more functionality with it. And that, I guess, so my understanding is Revault is sort of, is like a precomputed vault idea that allows you to do this function of, you know Saving the, like, stopping the coins from getting sent in a way that you don't want them to get sent. What do you, what do you say?

Okay, two things. the first one about the vault. So the original idea behind vault, I'm not even sure it had the, kind of the escape, escape mechanism with the extra wallet. It's more like enforcing, policies, kind of like limits on how much we can spend or where we can go, things like that. So the The, the typical like design is that you have a wallet, but if you try to spend outside of this policy, it just goes back into the same wallet, right? So in the original idea, you just have this same wallet. But then, it really makes sense that if you start having this kind of weird transactions, the attacker might just find what doesn't trigger your policy. And so it makes sense to have a panic button, that would send your funds, in another wallet you already control, right? So that's kind of why we have the, well, we And every kind of now, vault design has the, the escape hatch, the emergency mechanism. but technically, you could still call a vault, or you, you should still call a vault, a system that just send back to itself if, you try to cheat, right? the pre-computed stuff, makes sense. we are using pre-signed transactions in Revault, but we don't do pre-computation. So our design, and that's what make it, really interesting compared to the prior, the prior ones, like the ones From Brian Bishop, is that we don't have to precompute, for example, amounts in transactions. So, in the model of, of Brian Bishop, the problem is that you have to basically set up in advance all of your transactions, like many, many, many, many steps, and then you transfer the exact amount of money that you were designing in your vault. and if you made a mistake there, if the, the amount of Bitcoin you're sending, is wrong, well, too bad. Because all of the other transaction are spending, you know, the wrong amount then. with Revolt, you don't have this problem, and that's what makes it practical, is that it's just a wallet from the user perspective, so you can send any amount, and then you still are protected by the, by the design. the main trade-off to make that happen is that it only works for a multi-party, setup, so you need to have multiple people. It doesn't work for a single party, like if it's just for you and you want to have a setup work with Revault, and that would work with brand Bishop model.

Gotcha. And I guess the other one people talk about is the requirement for a, like a recycling or a refreshing of that UTXO. It's not just kind of like put 'em in there and it's good for ten years. The current model, as I'm understanding, you tell me if I'm missing this, is, that you- Is it like on a yearly basis or some period that you need to recycle that UTXO and therefore re-spend it?

Not for Revault. for Liana, which is not a vault, you need to, but for Revault, you don't have to. So, the trick in Revault is that you basically have an N-of-N multisig, and then if, the, the, like what we call the manager, so the person who is trying to spend, the person you delegated the funds to, so basically who you want to enforce, And everything, for. If this person tried to spend, they actually have to then trigger the unvaulting, so they just push a pre-signed transaction, and that's when they request the funding that the timer starts. So you don't have to rotate, because it starts only at the time they request it. So that's the cool thing with the pre-signed transaction stuff. now the bad thing about pre-signed transactions is that it's really hard to predict the fees in the future, and there is tons of attacks today, on the mempool. about pre-signed transactions. So that's what makes it extremely complex. So trying to make it, you know, usable in-increase the complexity, the technical complexity, of Revault.

Yeah. Okay. So let me ask this question. So there'll be a lot of listeners who are just thinking Why not just multisig? You know, like, why even do any of this stuff, quote unquote, just do multisig? What would be your answer there?

Yeah, no, I mean, multisig is great for some people. the, the Revolt design actually originated from a client, that was, asking me to work on a, on a specific infrastructure for them. and what they wanted is that, they, they had a hedge fund, right? So multiple co-founders having a hedge fund, but they wanted their traders And, and you know, things like, only a whitelist of addresses they can send to. So what they wanted really is that the people who are going to use the funds would have these restrictions enforced on layer one directly. They didn't want to trust any third party, but it's still, you know, their funds, not the traders' funds. And that's why, it is, it is a vault, and a multisig here wouldn't help because the multisig would require, the owner of the money to, you know, sign And co-sign on every transaction that the trader do, and they didn't want that. They wanted to delegate the responsibility to the traders, but still within, you know, spending policies limits, and, and that's what Revault does.

Gotcha. So I would say it started then out of a business need, a business use case as opposed to the typical hodler, long-term hodler case who's not gonna touch those coins for five years, ten years longer. So yeah, that would be, I guess, that's maybe the reason why for this particular case what we're talking about, the vaulting case. so then- Why don't you answer that question from a Liana perspective as well? Like, why use Liana? Why bother with these complicated multisig, miniscript, all this expanding and decaying multisig? Why bother with all that? Why not just multisig?

Yeah, that's a, that's a great question, and it fits us extremely well. So basically, the, the revolt, thing was to protect against, theft. So to really restrict how money can be spent. one of the issues with it as well that we didn't cover is Is that the trade-off with the current, Revolt mechanism is that it doesn't protect you against loss. You really have to make sure you have your keys and your backups because if you lose a single key, you would actually lose your funds. and so Liana is the complete opposite from, like pretty much from everything, from Revolt. It's, it's a protection against loss. So it's really trying to help you have more redundancy, make sure that if you lose a key- You have backups and things like that, but it isn't a protection against a five dollar range attack or any kind of, you know, physical threat or things like that, which Revolt does protect you against. So it's a very different concept. another thing from, for the, you know, maybe less technical listener, Revolt is a complete infrastructure that you have to deploy. it requires a bunch of servers, it re- it's very heavy. It's not a wallet, right? It's, it's a, it's an entire thing. You need watch The coordination server, you need a lot of things. Liana is just a Bitcoin wallet, so very different. both of them are using, Miniscript, so Miniscript is like a, a way to, to do Bitcoin script in a, in a safer way, so that's kind of new. but both Revolt and Liana are using Miniscript, but it's just the things we're using or the way we're using them are different. So both of them use Timelocks, but Liana really is to protect yourself against loss, while Deterrent against

an attack. Oh, interesting. Yeah, okay. And so, yeah, it's interesting to kind of get further into the detail around these. So, I guess it's important to understand the different uses and the different products here, because one is more about, let's say, business use case and having policy restrictions on How much Bitcoin can be sent out of this vault, as an example, whereas Liana is maybe we're thinking of that more from a recovery, loss protection, inheritance kind of use case, but the idea being instead of trusting a custodial platform You are relying on a, a deeper level of Bitcoin coding and Bitcoin script protection for certain You know, protections in a way of saying, okay, this is now a two of three or, et cetera, the different types of multi-signature, if I got that right.

Yeah, exactly. And, also, you know, Revolt sounds much like sexier than what Liana does because that's really the dream, you know, how can I make sure nobody can ever steal my coins even under threat? how can I, you know, make sure I have spending limits? Everyone wants this kind of stuff, right? We really want it. But Like Revault is extremely complex. That's not something, people and businesses are using. Now we have the proof of that, right? We, we built Revault, but nobody's using it in production right now, so that gives you an idea of the level of complexity. Liana, very different. It's just a wallet. You install it, it works. you know, there's a lot of users right now, so it's, it's really something that's basically install it and you can run it. So very different in the, in the complexity level

I see. Okay, so let's, let's talk a little bit about Liana then. What can people expect to see, if you could give a just a bit of an overview and maybe just overview what are some of the hardware devices that support Liana for now?

Okay, cool. So, yeah, one of the things, so let's start with Liana itself and then, then the hardware. so overview is that Liana started only as like a, a desktop, wallet, desktop client. So you go to the website, download it, it Computer. it works on, you know, Windows, Linux, Mac, whatever. it is fully open source, so that's also a cool thing, a proper free software, you can fork it, you can do whatever you want with it. it's built-- the desktop version especially is built, with like the proper sovereign, you know, you control your coins, you control your full node, you control everything, philosophy. People don't really realize that, most wallets that you're using, either on your phone, on your computer They do still connect to some internet services for whatever reason, you know, for fee estimation, for the price of Bitcoin, for maybe your even like your node, the backend, right? It needs to talk to something. Lianna doesn't do that. So that's the first kind of heavy thing about Lianna for people who don't realize that today, is that, currently it doesn't talk to any external server. When you install it, it, it's, it's done, it's on your computer, we don't know anything about it, we don't know how Users we have, which actually is an issue for us as a company, it will either connect to your local Bitcoin Core full node or it will actually download Bitcoin Core and set it up for you in a prune mode, but still on your machine, right? So you're not even connecting to the Bitcoin network outside your Bitcoin Core node is. And so, yeah, currently you don't have a, price estimation, you don't have fee estimation, all of that is still kind of manual. But otherwise, it's, it's a very normal, Bitcoin wallet when you use it. The only difference is really the setup where you actually need to, you know, decide, okay, what setup do I want? How many keys do I want? What do I want as recovery things? And that's where the hardware wallet come in, right? So currently Liana, offers you, if you want, to use Implemented mostly for testing purpose, you can also use it as like second factor, I need to be on this computer to be able to spend, things like that. but yeah, you, you should just plug in your hardware wallet. hardware wallets we are supporting are Ledger, Specter DIY, BitBox and ColdCult. we are actually, well, Jade is integrated, it's working from the, the, the master branch on GitHub, but it's not officially released yet. So, we will release the Jade support in the next version. The work we need to do, so it's not as easy as for other wallets to implement hardware or to, you know, just support the hardware wallets, because the hardware wallet also needs to support Miniscript, and that's, you know, that's require quite a lot of work on their side. So there is this, big kind of, thing that we have to fight with, which is when we want a hardware wallet to support Liana, we really have to do a lot of politics behind to convince them that it makes sense to spend some engineers' time to Miniscript, because we know Miniscript is the future of Bitcoin and probably every single wallet will use it in the future, but it's not the case today. there is like basically us, my Citadel support Miniscript, and that's, yeah, that's basically it today in term of like existing, desktop wallet, that support Miniscript. So for the hardware wallet manufacturer, there isn't a huge incentive today to implement Miniscript, but something like Liana is really helping, so we're very proud of that and, yeah

Gotcha. And so then, let's talk a little bit about the different possible setups that you can use with Liana, right? Because, you know, most users probably-- most listeners are probably used to just a standal-- standard single signature wallet setup with no, you know, fancy bells and whistles, no miniscript, or, or maybe they've used, you know, multisig with some kind of guided provider. Now, even for us at Swan, we have Swan Vault, that, you know, and so that's an example. Or they may- Used, let's say, Unchained, they might have used Unchained, they may have used multisig in that context. Maybe the more advanced users may have played around with Specter and Sparrow and, you know, done their own multisig, so that's probably the level most people are at, right? Like if you're listening to this podcast, that's probably where most of, most of the listeners are at, right? In terms of having a single signature, either using a guided multisig or if the advanced users doing, doing the, doing it themselves. How will L

This is, yeah, this is the great question, and, we really try to answer it, but it, it's difficult because there is a lot of ways to, to answer it or to use Liana. So I'm gonna answer from different kind of personas, so maybe people, who are listening are going to be more like, "Oh, I fit this one, I understand." but I don't expect people to understand every single use case. another thing, just before I do this, is that you can combine all of these in Liana. You don't have just one recovery path, you can have as many as you want. So you can have, you know, your backup, your inheritance, and et cetera, et cetera. So you can combine them And people can just mix and match what they think, would, would fit for them. so let's say the, the one people are using Lianna for the most today is actually the inheritance. So it's kind of the more complex one, maybe, but it's also the one that, there isn't no great solution on Bitcoin today except Lianna, in my opinion, to do it. Lianna isn't perfect, but it kinda works. So the issue with inheritance is that we want someone else, that's not us, to be able to Access our Bitcoin without us being here. And that, from a security perspective, is terrible, because that means we're actually sharing our Bitcoin with someone else. So how do we make sure that this someone else doesn't actually take the coins when I don't want them to take the coins? So when I'm still here, basically. And so the, the kind of workaround that other companies are offering today, the ones that are offering kind of inheritance stuff Is that, it's usually part of a two of three or the equivalent of a two of three, where if something happens to you, then the company has to co-sign when the beneficiary asked, for it, right? But that's, you know, trusted third party situation for two reason. One, you're trusting them not to co-sign with the beneficiary when you are alive, which could result in theft, and two, you also trust them to be here when your beneficiary actually needs the money. Because if they aren't here anymore or if they refuse to sign, maybe for regulatory reason or whatever else, you know, maybe, oh, well, the law says we can't co-sign stuff, then your money's gone, right? It, it's stuck forever. So that is the main issue with the current services that exist, right? There is two things, there is the theft and there is the potential, inability to sign and then the funds are lost. So the alternative to it, which most Bitcoiners are doing today, is actually to write down their mnemonic on a piece of Give it to the family and you just hope your family is securing this mnemonic properly. They aren't going to let it, you know, on the coffee table at home and somebody else can just take it and steal your money. And you're just trusting them to not access your coins, which is kind of reasonable. Usually you trust your family, but do you really trust them to secure this mnemonic as well as you would? Do you really, you know, are they gonna be still, are they still gonna keep it in ten years? You know, you don't know how when you, when you, So there is a lot of weird question there. what Lianna does, very different is that we're using Bitcoin time locks, so we haven't really talked too much about that. But basically, we aren't, we aren't the company enforcing this. It's just Bitcoin that enforces it, we're not a trusted third party. what this time lock does is that in a Lianna wallet, you can have multiple keys, kind of like a multisig if you want, but in this case, it's not a multisig, where some of the keys aren't Right now. They become valid only if you don't move your funds for a specific amount of time. So what happens in the typical inheritance situation is that I have a hardware wallet, you know, single sig, that's my normal day-to-day, spending thing for, for Liana. So I just need my hardware wallet to sign single sig transactions. User experience is exactly the same. But if I don't use my wallet, if I don't move my funds for one year, then the wallet of my family, the backup I gave them or the hardware wallet they have Will be able to also spend the coins. So it's not deactivating my hardware wallet, the funds aren't moving by themselves from one wallet to the other. The, the wallet is Liana, right? It's just that now instead of having just one key that work, you can have either of these keys, being able to spend, but only after the time lock expires. So that's one of the use cases. We can talk about the, the problem about rotation of coins and stuff after, because they concern all of the setups, right?

Gotcha. Yeah. One other question just on this, that other key This other, let's say the other family member, you know, is run-- they need to also be using one of these four hardware wallets, right? Like, currently, it needs to be one of the Miniscript supporting hardware wallets, right? Ledger, BitBox, Coldcard, Specter, DIY, or Jade in the future, right?

Yeah. So Yeah, you can even set it up for them, you could also just give them a mnemonic that you already, you know, got the expert from, so they don't really need a hardware wallet right now. They only need to be able to sign when something happens to you. So they could import this mnemonic on any of these hardware wallets or any of the future compatible hardware wallets. So if it's not really a, a, a problem you want to deal with right now, like what hardware wallet should I buy for them? Just give them the mnemonic, you know, it's fine.

Time locked one. And so the other thing is, you'll under-- you'll be able to understand and explain this better than I can. Can you just explain a bit about the time locks and what the limits of those are today? Right, as I understand, there's CLTV and CSV, and, you know, there's a realistic limit level of how long you would want to actually use that time lock?

Yeah. So this is more technical. there is two types, well, yeah, there is two ways of doing time locks, in Bitcoin Core, so in Bitcoin, You have, as you were saying, check lock time verify. this one is with a specific date or specific block height in the future. That's what we call an absolute time lock. So the time where they order key or where the key becomes valid is a specific, you know, time in the future, day in the future, basically. that's not the one we're using. I can cover why, after. The one we're using is OP CSV, check sequence verify. This one is called a relative time lock. So It's relative to the time where the coin, the UTXO, was created. So when the transaction creating it kind of was mined on the Bitcoin blockchain. And so the timer starts at this time when the transaction was mined, then you have this time lock counting in term of blocks or time, and it will only become valid the other key, once this time lock is expired. the first one, the check lock time verify, has a very, very big limit Limit in the future, I think it's like ten thousand years or something or nine thousand years. So if you do a mistake or whatever, you can really lock your funds for a long time, but that could be fun for some use case, I don't know. the UpCSV, the one we're using, has right now a pretty short maximum limit duration. It's one year and three months. So that's the very maximum you can have a relative time lock today. So that means in, in what I was explaining earlier, the maximum you can set in Liana, is one year and three months. So, you know, if, if you don't use it for longer than that, if you're just a hodler and you never touch your coins, then your time lock will expire. It's not really a problem as such, because your family is probably not gonna try to steal your money, but the problem is that the benefit from using Liana, this time lock thing, is kind of void then, in that case. there will be ways to increase this maximum in the future, so there is ways to do that through soft, soft forks in, in Bitcoin. But currently, of course, there is no such proposal because nobody's using time locks. Only, you know, Liana is bringing that right now. then you have also Lightning, but the time locks are much shorter, we're talking about like a few weeks. So, yeah, once there is more demand for time locks, for sure we will have ways to increase that to multiple years, but currently the, the limit we have is one year and three months.

Okay, gotcha. And so can you just talk us through how to plan, you know, the, how much to do in that case? Like three months, six months, one year? Like what, what's your kind of thinking there, and how is the user gonna get guided there?

for the inheritance use case we were talking about, I would put the maximum. I would put one year and three months. The main issue would be really for the family that if something happens to you, that means that they might have to wait up to one year and three months, especially If you were very regular in your, in your use of the wallet, then probably your time lock are like push at the maximum, so that would be one year and three months. That might be too long for some people, right? If all of your money is in Bitcoin, for example, you might want a shorter time lock. The problem is, then you need to keep using your wallet a bit more regularly to keep pushing this time lock in the future, right?

Back to the show in a moment. This show is brought to you by CoinKite dot com, the leading Bitcoin hardware Such as the Coldcard, the new Coldcard Q, they have cheaper devices such as the Tapsigner or the Satscard. You can really pick your own security model with CoinKite, and I like using the Coldcard as part of various setups of my own. You can use it in such a versatile way, whether that is single signature for beginners, you can have a passphrase, you can use SeedX, or you can use it as part of multi-signature. So there's so many features and, ways you can use this device or use these devices. And with the new Coldcard Q, you can use QR codes, and so that's really easy, provides a whole new kind of user experience, and it's got a full QWERTY keyboard, so it's easy to type in seed words or passphrases and all kinds of things. It helps you when you're managing different wallets. So if you wanna get your devices, go to coinkite dot com, use code Livera for a discount on your Coldcard. Swan Bitcoin is the lead sponsor of my show, and as many of you know, I also work at Swan. Swan has a Into Bitcoin and create the best experience and to be the best way to buy Bitcoin. Now, there's a big update the team have been working hard to make the Bitcoin experience and buying Bitcoin really slick. So now you'll find if you're signing up as a new Swan Bitcoin customer, you can get signed up in just a few minutes, and so you can just go from zero to Bitcoin in a few minutes. So this makes it really easy if you have friends and family who need an easy pathway to sign up, you can be standing there right with them and tell them, "Hey, go to your app store Android, search Swan Bitcoin, and you can sign up, and the process will just be a few minutes. So this is a great new update, and one other big update is that Swan is now rolling out zero fees on your first ten K of Bitcoin buys, so your friends and family can get started for free in terms of Swan fees. And not just for new users, but for existing Swan customers, you will also get your next ten thousand dollars of Bitcoin buys free in terms of Swan fees. So if you want to recommend Bitcoin, make sure you are out there They're telling people to search Swon Bitcoin in their app store so they can get started in just a few minutes and have zero fees on their first ten thousand dollars of Bitcoin buys. That's Swon Bitcoin in your app store. And finally, this show is also brought to you by mempool dot space. Mempool dot space is the leading Bitcoin and blockchain visualizer. You can use this to search Bitcoin transactions, so you can take the TX ID and paste that into mempool dot space. Now, of course, you can run it yourself if you wish. You can do all kinds of things over on mempool dot space, and most importantly, when you are about to send a Bitcoin on-chain transaction, you can check the dashboard there and use that to target your fee such that it's a level that's appropriate for you. If you wanna get into the next block, well, you wanna look at the high priority fee. Over at mempool.space, they are continually rolling out new innovations and things. So recently, they brought out mempool goggles, which is a great way to look at the different transactions coming into Bitcoin's mempool. Now, they have different tabs. They've got a mining tab, there's a lightning tab, you can even explore liquid as well for those of you interested in that. Mempool.space are also doing an accelerator program, so mempool.space/slash-accelerator is the place to go and There. And now back to the show. So just one other implication I wanna talk about there, because let's say the hodler is kind of, they're using this for their deep cold stack, right? And then maybe they've got like a day-to-day wallet that they're kind of using more regularly, and so- For, like you were saying, for that deep cold stack, maybe they only touch that once every four years, you know, like maybe they just don't touch it that often. So in this case, like if they wanna use Liana and they wanna use OpCSV with one year and three months time lock, that means they've gotta kind of remember to come back and refresh that time lock, to make sure it stays at the one year, three months.

Exactly. That's the, that's the main drawback of, of Liana. it's that, yeah, in this case, you should, very much do at least one transaction every year to, you know, refresh these, these time locks. So that means it has two, two bad sides, right? The fact that you need to do a transaction, so that's one thing, but that could be seen as well as a good side because at least you know, you know, your keys are still, working and et cetera. So it's still good practice to test your keys from time to time. but the other bad thing is transaction fees. So you need to do on-chain transactions to do so. So you have to pay transaction fees, every year basically to rotate your coins. So that's just, you know, the way it is. It's not money for us, it's money for the Bitcoin network. But this is one of the, of the drawback. And back to the very beginning of this, of this chat, the reason for that, or at least- The alternative will be when we have covenants, then we won't need to do this. But currently we don't have covenants, so for me it's like, it makes sense for me to do something like this, rotating my coins once a year. If I really don't use them, it's just, you know, one transaction every year, I can totally do that. But for sure, for some people, depending on their setup, it might not be reasonable.

I see, yeah, okay. So then, just coming back to my question of what type of wallet is this, right? Because there might be some users who are in the context where they have like a deep cold hodling stack that they rarely ever touch, and then more like a day to day, let's call it a warm setup that they're using. In this context, is Liana like, what category would you put Liana in? Or would you just say you would just use Liana more like your day to day? Warm wallet, and the idea is that you're just, do you get what I'm asking?

Yeah. Yep, I totally get what you're asking. I would say it depends. For inheritance, of course, what you need is your cold storage to go to your family, right? So for inheritance, either you use Liana, and you need to move your-- Well, you need, you should move your coins once a year to make sure, you know, there, there is still this time lock being enforced. or you need to find something else.

family, if you have, you know, a setup with a warm wallet and a deep cold storage. But for the other use cases that we can talk about now, actually, it totally makes sense to use Liana as a, as a hot or warm wallet, not hot, but let's say warm wallet.

Gotcha, gotcha. Okay, so, yeah, so we've spoken about that. I guess that case we've spoken about, probably the user, you know, demographic there is maybe like the individual hodler who wants to make sure his coins pass inheritance wise. Now, let's talk about some of the other cases.

Yeah, yeah. So in, in the profile of the inheritance one, there is also the ones that really don't want to trust a third party. if that's important for them, there is no alternative except giving a copy of your mnemonic to your family, and that's There is just, there is nothing, it's just strictly worse to just give a, a backup to your family if you don't want any trusted third party. then the other things are like more, you know, what, what applies to us maybe Bitcoiners, today, if, if inheritance isn't your, your main thing. So for some people, let's say the most, the, the people who are just having some Bitcoin and they aren't, you know, full-time Bitcoiner, they don't have time to learn everything about Bitcoin, You know, well, they want to be sovereign, but they don't want the risk of losing their money. Liana is actually pretty good for that, because you can get something in between, what would be, let's say, a third party custodian, so maybe leaving your money in, in Coinbase, right? or being in self custody. And we're going to talk about the two of three, like, for example, the, the Swan Vault. But, here what you can do is actually that you can have the best

Have your own key, that's the only one that's valid right now, as long as you keep, you know, using your wallet, you are fine, you're fully sovereign, your key is your coin. But if you really lose everything, if everything goes bad, you know that you can put a, for example, a custodian key or custodian keys, if you want a multisig of custodians, you can do whatever you want. You can do custodian keys, in the recovery, in the recovery path. I'm saying custodian because let's start with that. And so you could say that, you know, I'm fully sovereign, but if I lose everything, then I can go back to the model of a trusted third party that can actually send me back my coins. So this is more like for the user that's currently leaving their funds in an exchange because they think they are safer this way compared to being in self custody. Now you can have like, you can be sovereign, and if really something bad happens to your keys and your backups, you can still have the recovery from a third party custodian It doesn't have to be a custodian, that could be your friends if you want to do like social recovery, that could be your family, so when you onboard someone else to Bitcoin, let's say, someone very close to you, right? Your family. Typically what Bitcoiners do today is that we keep a copy of their mnemonic because we know, if they don't really care much about the Bitcoin, we know they're gonna lose it, and then the next, next bull run, they will come back to you and they will be like, "Oh can you help me out? So this is just the way it is. You shouldn't do that, but people do it. So now you could have your key in their setup, that's behind a time lock, so you can't steal their coins as long as they use it properly, it's fine. If they really lose their keys, then you can help them out, recover it. So it doesn't have to be a custodian, right? It could be, multi-sig of friends, it could be anything. So this is, another use case then there is another case you can do, which is what we call the safer backups. this one isn't clear to people yet, and I think it really is the, the main one in term of like making sense, but people don't get it. So I'm gonna try to explain it, and you tell me if I really don't explain it correctly. Currently, we use hardware wallets. Why do we do that? We do that because on a hardware wallet, the mnemonic, the seed, is actually secure. We know that if someone finds your hardware wallet, in the worst case, probably they can't extract the seed. If they don't have the pin code, they aren't going to be able to steal your coins. And this is the main reason why we use hardware wallets. So why is it that the first thing you do when you actually set up a hardware wallet, why is the first thing to actually extract the mnemonic and write it down on a piece of paper? To me, that makes no sense. The whole point of the hardware wallet is that the mnemonic shouldn't or the seed shouldn't go out of it. And because a hardware could die, obviously, we need a backup of it. But the backup we have is the same key, so if someone finds the backup and there is no passphrase and things like that on top, they can just steal your coins. Why wouldn't the hardware wallet generate a separate seed, one that we will put behind a time lock, and that's the one you write down? So now you have actually technically two keys. You have the hardware wallet, that's the normal key that can spend any time, but then the mnemonic, you need to actually stop using your hardware wallet for, I don't know, six months, one year, for the backup mnemonic to be, valid. And that's pretty cool, because that means that if there is, you know, somebody breaking into your house and finding this mnemonic, You can still move them with the hardware wallet, no worries, and that's much safer than just having a clear text mnemonic, at your place. And again, you know, people mitigate that today with passphrases and things like that, but, again, either their passphrase is just not secure because, you know, it's a, it's a weak passphrase and they try to memorize it, or it's a very secure one and sometimes they don't do a backup of the passphrase and then they lose it. So here we just have a, what I think should be the fault, of every hardware wallet and even like software wallet is that the backup you take, it's a backup, it has no reason to be active right now, it should be behind a time lock no matter what, because it's not a key you need, you, you need it only if something really bad happens, to your hardware wallet or things like that. So to me, that's like really important use case, but it's very hard to explain because nobody is used to this.

Yeah, this requires a lot of, you know, really thinking about what Bitcoin is, how Bitcoin works. You know, I, I think probably listeners of this show can kind of grasp that. But it's, gonna take a lot of work to kinda get that idea popularized out to the broader, you know, non interested, audience, let's say. but yeah, as I'm understanding you, you would have two sets of keys, one that's in the hardware wallet per se, and then one that's like a, a time locked backup. And the idea is that you would keep this backup somewhere else, maybe you would have some kind of tamper evident bag or some kind of, you know, yep. And the idea is that you would-- the user

I'm doing a quarterly check of my, my backup bag and make sure it's not being tampered or opened. Oh, okay, it's safe. Okay, I'll come back next quarter. But if they come back and they see, oh, something's wrong, okay, quick, now I need to rotate out of this setup into something else, et cetera. But the idea is that this would help defend the user from Yeah, I guess third party

access of the backup. Yeah.

Right. Yeah. And so, I mean, in that model, you're still kinda rely-- you're still, you know, pretty much relying on the hardware wallet having not-- your, your, your main seed not having been tampered with or messed with somehow or evil maid attack, that kind of thing, but- This would at least, in the event of hardware wallet failure, device failure, you've still got that backup, and maybe it's a six-month time lock on that backup or whatever, and so, you know, I guess the other ac- thing is maybe you're, maybe you're destitute for six months, but maybe in the future there'll be kind of like lenders or loans to people who sort of say, "Oh, see, Kevin, I see you've got six months time lock left on your thing, let me forward you, you know, ninety-eight percent of the Bitcoin now Interest rate on it and something like that, so you're not destitute for six months, something like that.

I, I really think that's, that's the way things are going. you can also see insurance, starting to pop up, so with Anchor Watch that's also working on the same type of wallet, because insurance companies, feel much better to cover your coins if they can see, you know, okay, the coins are going to be unlocked in the future, yeah. Exactly. Yeah. So that's, that's really cool, Is like, okay, sure, fine, the coins, we're gonna get them in the future, so it's perfectly fine.

Yeah, interesting.

So,

yeah, I guess the, the thing is, this is gonna be difficult to explain to end users, but maybe the way it actually gets given to those end users is more like through a service, right? Like, there's a company or a service that offers this professionally, and maybe in the background, yeah, they're using Miniscript, they're using Liana, they're using some of these tools, but the user feels like, oh Coins, I have a, you know, I forgot my password, right? Like that's, that's in the end, at the end of the day, that's what a lot of, let's say, end users of Bitcoin, they want that. They want this kind of I forgot my password feature. Now, for those of us who are more in the kind of hardcore sovereign Bitcoiner camp, we sort of don't like that today because that implies custody, it implies trusted third parties. So this is, I guess, a way to try to blend those worlds. optimistically, let's see if these worlds will blend.

Yeah, and, and on this actually, there is a, so there is a lot of like, kind of purity check in the Bitcoiners' side where like, oh no, it says third party, so it's bad. Not necessarily, right? Even the two of three multisig thing, if it's implemented, you know, against loss, for example, this third party, the trusted third party, can never steal your coins. So you are kind of reducing the trust, that way, and you can Bodies that are fine in your setup. and I think one of the things that kind of scare people in, in one of our, products on the website, which is what we call the safety net, this like custodian key that you put as a last recovery, you know, just in case something go wrong. They see that and they are like very scared, they're like, "There is custodian in this, that's a bad word, I don't want this." But the alternative is that in the exact same setup without the custodian. If you reach that level, it means you lost your coins. So if you lose all your keys, you lose all your backups. Now you have the, the option, or you had the option to set a custodian as a recovery, or you don't because of purity, whatever. If you don't have it, you lost your coins. That's up to you, it's your choice, but it's not like Worse in any other way for the normal use case, because the custodian key is never valid unless, you know, you don't respect the rotation of coins, of course, or you really, lose all your keys. So- Yeah.

So how far ahead can that, can that be set? Like five years, ten years? Like how can that be set?

It's still the same, still cannot. So it's still one year and three months maximum for this, which is the picture potentially. Okay. So that's kind

of the main, like, the main thing would just be like Taking control of my coins.

Exactly. So we do have cool mitigations against that actually. maybe that's a little bit technical again, but I think it's worth mentioning. a normal custodian or even a, a key in a two of three multisig, like the ones you have, you need the custodian to know the coins, right? You need to, you need to be able to see the wallet, otherwise you can't do anything with it. Well, in our situation, with Liana in this setup, you don't necessarily have to share-- or you don't want to, if you don't have to, you know, like maybe privacy reason, you don't necessarily want to share what we call the descriptor with the custodian. So in that case, that means that the custodian has absolutely no clue how many coins you have, who you are, you know, they have no vision. They don't even know if their key is being used. of course, you have to, you have to basically pay them a subscription. To keep this key safe, but they don't know if you're actually using it, they don't see anything. So even if the time lock expire, in that case, they can't spend it because they don't have the descriptor. The issue with this setup is that you still need to provide them the descriptor when, you know, when you need, but you could, you know, basically deal with a third party. You could keep that in a

separate, you know, somewhere else, in a USB stick, in a private cloud, encrypted, whatever. So there's

all kinds of other ways In a, in a, in a, in a, in a, in a drive, in a private drive or whatever, because this isn't, you know, there is no private key in it, it's bad for privacy, but there isn't no spending problem. you can also deal with like other third parties, you know, keep it in a safe, keep it whatever, even if someone get access to it, they can't steal your coins. So this is a really cool setup that people don't yet realize the power of, that you can have actually kind of a technical insurance You don't have to disclose who you are, they don't need to do KYC at this stage, you don't need to give them, the descriptor, so all you have is an xPub that someone else is storing, and they don't know anything about you. The only thing you have to do is to pay them, you know, once a year, and that's it.

So let's talk through a few of these other terms. I've seen these on your website, and I think these are just gonna be generally interesting for people to learn a bit about and at least to

Is an entire thing we haven't covered yet. typically, in my opinion, multisig, i-is used more for like businesses. Sure, you can use it for your own coins, but the kind of risk you are, you are mitigating doing a multisig yourself is really, you know, you have so many layers that, that it's a, it's a whole episode again, like for example, having different keys in different locations so people can't threaten you at any time to access your coins, or you're trying to mitigate a potential- Actual, hardware risk with one of the vendors, so you have two different vendors for the hardware wallet, things like that. That's pretty advanced stuff, it's not the, the normal Bitcoiner. But then when you have an organization, a company, for example, with multiple people controlling the money, then you need a multisig, that's just how it is. And so the, the typical way of doing multisig today on Bitcoin is doing a two of three, doing a three of five, it's usually these numbers that keep, keep coming up. Because if one of the key is lost, and that happens, then you still want to be able to access the funds. So that's why you never have a three of three, or it's extremely rare, because the risk is just too high to lock your funds forever. So today we do that, two of three, three of five, something like that. with Liana, you can actually do something really cool, which is having a n of n, so a very strict multisig, three of three if you want. But if one of the key is lost, you can

Say after six months. So if one of the keys lost, you still need to wait six months, but then you can access it. you can keep doing layers after layers, right? The two of three could become a one of three, but that's not very secure, so it's not that interesting. we have another one that, we're calling an expanding multisig, and I think this one is actually the better one. So the expanding multisig, instead of reducing the security over time, it's actually adding more keys. So your three of three can become a three of Other key in the future. So this key is not valid right now, there can't be any collusion in the, in the multisig to try to, you know, remove you from signing and get someone else. but if one of the keys actually lost, you can have an extra key that might be kept, I don't know, with a solicitor or with your board of director or something like that, and that will become valid in the future. And, and this is really powerful for companies. I'm just gonna give you a, a practical example of today.

A stack of Bitcoin, and we have a two-of-two multisig right now. So I cannot move the, the coins alone, Antoine cannot move the coins alone, we need to co-sign every single transaction we want to do, so the two of us. but that's extremely risky. We travel a lot, you know, we could lose the key, but let's say we're not going to, it's not going to happen, but something could happen to one of us, and of course, I have no way to ac-- to access any of the

So instead, what we have is that if something happened to us, the two of two become a two of three with a, with a third key. So, yeah, that's a, that's a good way to not reduce the security into like a one of two where it would be very bad, but actually we increase it, to a two of three.

I see, yeah. And as you said, that can help even in the case of co-founders, arguing with each other or if one of the co-founders lost their keys, then that third key can be held by Board of directors or some other, yeah, yeah, advisor or some other person for the company, and, that can, help them get out of a, a jam in that case. Yeah. So typical,

typical arbitration, setup as well. You know, there is a lot of kind of like smart contract that, that requires two people to have like an agreement, you lock some funds between the two of them, if there is a disagreement, you have an arbitration key that become valid in the future.

Right. And so one other question, just dealing with unconfirmed transactions, right? Like in some of these scenarios where you've got like a complicated thing, but maybe the fee went out too low, is there a way to kind of RBF that, or are you gonna be kind of, or, or is it just kind of relying on, you know, full RBF or using some kind of accelerator to, to kind of accelerate that transaction?

Good question. this is one of the big misconceptions about Liana, and that's because a lot of people confuse the Revolt and Liana thing. Sadly

They, they saw both of them, coming from us. Revolt has pre-signed transaction for the way it works, but Liana doesn't. Liana is just a normal wallet, so the transaction are absolutely normal. so yeah, RBF works the, the normal way, yeah, we have RBF, in, in the, in the software, you just click the button to increase the fees. we have CPFP as well, so, you know, all of this is like a normal practice, it doesn't change anything to your

Gotcha. And so just, just to be clear, with Liana, you can set up the multi-sig using a single coordinated desktop app. Can you set it up remotely as well? Like, let's say you and I are in different countries and we wanna set up multi-sig together, do we need to physically be together to set it up or can we do it remotely?

No, you don't have to. So basically in, in Liana, so coordinator, we don't really have one right now, so you, you still need to exchange PSBTs. but anyways, so in Liana, one of the person will, will create the wallet, so it will be responsible to, you know, do th- go through the which keys we put where, but you also have an option to participate, in a, in a wallet. So that's what we would do, for example, if we were setting up a two of two between us right now.

create a new wallet setup, and the other one just do the participate in a new wallet. And I would have

to like send you my xPub or something for you to include it in your coordination setup process. Exactly.

And you wouldn't have to, use Liana for this if you, if you have another way of, of finding your xPub, and there is many software that give you xPub's, you could just send me your xPub and I just add it there, yeah.

Gotcha. Okay. Yeah. Okay. and then one other complexity people will probably face is Miniscript is early, right? Like it's extremely early, so maybe some of the tooling, maybe the way to kind of understand what am I signing, right? Because maybe when somebody's new and they-- and not even, not just for someone who's new, maybe someone who's already advanced, they may be looking at the device, you know, like it's a small screen or maybe the new device, the Coldcard Q, a-and they're trying to figure out, okay. What quorum am I joining here? What am I signing here? What is that gonna look like in your view, in a, in a, in a hypothetical miniscript future?

Yeah. So what we have today, it's not at signing, it's only when you, kind of load the wallet the first time, right? So when you register the descriptor, that's how it's called right now, very similar to when you do a multisig. So if you do a multisig, you set up a multisig on Sparrow or whatever, you still need to on the, on the hardware wallet. So it's extremely similar, in what it will display on the screen and things like that. it will display you the miniscript, policy on the screen. So that's annoying because, yeah, if you don't know what you're doing, you're kind of just checking it's the same as you have on the, on the screen of your computer. You press next, next, next. the device tells you, if one of the key, like if the, if the, if the private key of That your key is really in there. and but yeah, you do that once at the setup stage. Then when you sign transaction, it just says, you know, oh, you're signing from your Liana wallet, this is where it's going, and blah, blah, blah, you know, so it's still checking all the things, but you don't have to validate every time. we have been discussing a lot on how we can improve this flow to speak better to people, let's say, to be like, oh, this is like a inheritance setup where this is it would be great to say that to people, but sadly there is too many attacks possible, where what's displayed on your laptop screen is actually different from what we are sending to the hardware wallet. But if we don't display it, it's like a malicious

software app, yeah.

But if we don't display it and the-- it's the same logic, but it's not the exact same backup you have, you're not gonna be able to find your coins. So this is like a ransom type attack, kind of like what ransomwares do. It's not about stealing your Basically asking you money if you want your backup back. So that's why currently we're still displaying the entire, policy on the screen.

I see. So for now, you still have to be a bit of a nerd to understand what's happening. But maybe in the future, there might be standardized templates and standardized sort of ways it operates, and maybe that's how-- I'm, I'm speculating, right? I don't really know. There is, there is work

being done, but yeah, for now, there is no perfect answer.

In terms of transaction bytes and the size of the How does Liana, how do Liana transactions compare size-wise to like standard, you know, transactions people are doing today?

Yeah, so there is two types of, wallet, technically, you can set up in Liana. So you have the old school, SegWit v0 wallet, where, so before Taproot basically. So with this, you have to reveal the entire script every time you spend. So because there is more keys in your wallet, technically, your transactions are Heavier, but we also support, Tapminiscript. So that means that, you only have like Taproot basically, you only have to reveal the script of the, the, the path you're using to spend. So as long as you use it normally, like for your normal transaction, and it's not a recovery, nobody on the Bitcoin network will know you are even using Liana, and they will just see you as a normal single sig and the cost is also the same as a normal single sig. So basically, yeah, it's, it's a in term of privacy, in term of costs, when you're using the Taproot, version.

interesting. Okay. And because you're using the latest, latest stuff, because that's the feature, Taproot Miniscript is the feature you specifically want. So you actually, in a way, you want more people to be using Taproot because now you've got a bigger anon set to hide inside of, and just more people are using Taproot that way, so there's more, let's say, wallet support.

Yeah. And that's also great for privacy,

Because you're not revealing them in the spending path, so they have no clue which coins are yours or things like that. Taproot is, is great for this.

Yeah, interesting. So looking forward in terms of Bitcoin soft forks, covenants, things like OpVault as well and OpCTV What's your view on those? Like, are you in favor of those? Would they help you or not really?

covenants would be extremely useful for us, as a company in general. Like for every single, things we developed, the covenants would just make the user experience, probably like better, strictly better. another cool thing for us is that we have these products like Revolt and Liana that are working right now. So adding covenants to them is pretty much plug and play. That would be super cool for us, because we basically have a product that's ready, give us the covenants and we'll make it better. now the question is, which covenants do we want in Bitcoin? I personally, and I'm not talking for the company here, but I'm personally against the idea of having multiple ones. So I would like one, that kind of fits the use cases that we believe, are kind of what we want on Bitcoin. the reason for that is that I'm, like, once we have new- Things in Bitcoin, we have to maintain them forever. And so if we have one that's actually we realize, oh, that's actually not the one we wanted, and we add a second one, we still need to support both forever, right, in the future. And that's typically, you know, coders and they aren't really paid for that. Oh, I mean, they can get grants and stuff, but why would they work on something that nobody's using just because we have to support it and we made the wrong decision? So I'm kind of stuck into these two things. That's why

Every one of us in the company, it's just because we don't want to be part of the politics of it. we, we are, yeah, we are very biased. We want covenants very much, but at the same time, we realize that it will have a cost, on Bitcoin, on Bitcoin development. So we kind of, you know, we, we don't want to be pushing for any single one of them. We're like, give us any covenant and we are happy, but please do so in a smart way.

So, I mean, one thing I've heard people say is like, "BearCTV alone might not be-- it might, it might be a little bit better, but not like that much, because there's certain features that you don't have with that, and there's like James Obie's specific OpVault idea, which is kind of maybe more targeted for the actual vault use case, and then maybe there are other, More advanced or more powerful covenants that maybe other people are, some of them are worried about because maybe that's enabling things they are, would they would not like to have on Bitcoin. but I guess there's, there's different camps here in terms of what some of the developers and people want.

Yeah, and even, even upvote, would work for us, right? We, we don't need a, we don't need something more complex, even for Liana, upvote would help. one of the thing that, is kind of coding argumentation and In this debate, kind of, is that the use cases that are being pushed are usually said to be, you know, a need of the market, typically up vault, the, the use case, as you were saying, is vault, and the, the kind of, the, the kind of, advertising behind it is that companies want vault, we need up vault. I'm not too sure about that, and that's also the main, argument that Peter Todd is using, is that nobody uses vault today, and I'm in a good position to answer that question. I'm telling you, we have a vault, it works, it's just nobody uses it. So does it mean it's just a problem of UX? Or is it really that we are completely mis-targeting the problem? What do big companies use today? They use MPC, they use, you know, Fireblocks, whatever companies, they use stuff that we don't consider even secure from a cryptographic perspective, but that's what everyone is using, that's what, you know, Coinbase is using, everyone is using MPC as soon as they touch multiple coins basically. And so we're not going to be able to go to Coinbase and tell them, hey, we have a vault, please deploy it. That's what we thought. Because we really thought they would focus on the security first, and sure there is more complexity, but they know they have the best security there, and that's not the case. So I'm not sure if it's just a complexity problem, like some people are saying, and the, the vaults, no, sorry, the covenants are going to fix this, but, yeah, this is kind of, one of the arguments as well.

I see. it does, I mean, I guess this is one area where people, disagree a little because I've heard, some-- I don't wanna kind of dox an individual here, but there is an individual who-- I don't wanna get too into the detail, but I've, I've heard some other individuals who say, "Yeah, actually, there are some companies who do wanna use this kind of thing." Yeah. So, I don't know, maybe there's just different views in the community here. I'm not having a personal stance, I Say there is a demand. Absolutely. I don't know, I don't really know where, so, where it shakes out. it could also be, and as you, as you, as you rightly point out, people, a lot of people currently like the fireboxes of the world are using these MPC things because it's more easy for them to support shitcoins all off one thing, whereas like more Bitcoin focused and more tech focused, those people do tend to be more interested in using like native Bitcoin, like, I know, BitGo as an example, they have like a Obviously the Unchained and the Casas and the Swans of the world are using Bitcoin multisig, but, maybe, yeah, it's, it's a, it's a function of how popular shitcoins are for now, and then who knows, maybe in the future, Bitcoin becomes more, even more prominent, and maybe at that point there's a rotation back, and then maybe people do care more about vaults in Bitcoin. Who knows?

I, I hope, because, it's a really beautiful concept, and, when we have the covenant, definitely it's going to be cool. but yeah, the, the, the kind of argument of like it's an urgent need, I don't feel the urgency at all. it's really that, the, the thing is maybe it's, it's a want. We all want it Taproot folk actually, people were like, "We need Taproot now, we can do all the cool stuff with Taproot." And, it's been years and all the cool stuff isn't really there. The only thing that's really using Taproot is like the ordinal stuff. I mean, come on.

yeah. I mean, I would say there are, Taproot channels being used, like for some Lightning, people, and so there's something there. You're using Taproot in your manuscript, so, I mean, there's some Taproot uses

Expecting like im-immediate ad- adoption of everyone using Taproot everything, because, you know, it-it always just takes time, just like it took with SegWit, right? People were arguing with exchanges for so long, hey, when SegWit, when SegWit, you know, and it was, you know, it just takes time with these things. So I guess that's kind of where it's at. Yeah. one other area, just around organization security, because we've spoken a little bit mostly around the individual hodler and maybe like a family

Organizations where they might, you know, split up keys, use multisig, but there's, maybe they have more specialized requirements. Maybe they want some kind of co-signing server, maybe they want you know, more strict disaster recovery requirements, things like that. Is there anything you wanna comment on there at the organization use case level?

Yeah, even for individuals, but cosigners, cosigners are great. I'm a huge fan. The, the cosigner, what is it? Well, really a cosigner is like An emulation of a, of a covenant. it's how can you put policies, spending policies, but, you know, you have to trust the hardware or a company to, to respect this. But this is cool because it's kind of the use case people want, right? It's like, I want to make sure that, I'm not doing a mistake with, adding a zero too much, so I want to restrict my transaction to be zero point one Bitcoin maximum each of them, right? Or I would require to have like three signatures instead of one, this is really cool. that can also be, yeah, to, to check other things, you can imagine a lot of use case with cosigners. So cosigners are great, and, one of the issues of cosigner again is the trusted third party. So for two things, you trust it to actually apply the policy, well, that's kind of, you know, you have to do that before we have covenants, but you also trust it to not block you when you are actually, when you should be able to spend. So the cosigner The job, but that means it can block me from signing even when it shouldn't. And so something like that, use, used with Liana is great as well, because instead of thinking about using them as a recovery, we now think about Basically getting rid of them in the multisig. So imagine the two of two things with, with Antoine I was talking about. imagine it was not Antoine, it's just me, I'm a solo founder now, and, and I want a, a cosigner to make sure that, you know, somebody can't threaten me to move all the funds somewhere. if the cosigner refuses to sign every single transaction forever for whatever regulatory reason, I want that after six months, I can actually sign alone, I can remove the cosigner from my setup. Yeah, yeah, yeah. And so you wouldn't want to

be kind of stuck with the cosigner there, yeah?

Exactly. And you can do really cool stuff, like for example, you have a company A as a cosigner in your first thing. So you have Mikey, you know, Kevin, and company A as a cosigner. If, if company A doesn't sign for like six months Become my key and company B as a cosigner with the same policy, so I can actually switch or swap the cosigners, but they can never sign the two of them together, right? It's not a two of three with two cosigner, it's a two of two with me and the cosigner A or me and cosigner B. So you can do really cool stuff like that.

Right, yeah. So some of that is more advanced level, you know, thinking. So I guess some of this stuff is really kind of vaults and advanced self-custody is kind of where it's at today, and I appreciate that for some listeners, this can seem a little esoteric, like it's a little above, you know, may seem a little bit pie in the sky, but it seems that this is where, let's say, serious, you know, inheritance and serious insurance cases are going in the, let's say, five to ten year time horizon, I'm guessing, but it seems that is the way it has to go in order to have less trusted or let's say minimized trust, environment as opposed to today where most people are just kind of defaulting back to the fiat world, custodian, custodial solution, and just kind of having that extra trust there. So, we've covered a lot today, we've spoken about a lot of different things. I'll just try to, I guess, summarize a few key ideas just to kind of And make it clear for people. So, we've spoken about this idea of, you know, Revault, and we've spoken about Liana, and we've spoken about some of the different concepts that are involved, like using Miniscript with different spending pathways and some of the different hardware devices that are coming now that will support that to allow you to- Not have to trust as much in, in the case of inheritance or in the case of making sure that you, your backups haven't been tampered with, as an example. So I think those are kind of the, the main aspects. The main downside trade-off is, as you said, there's a cycling UTXO requirement, typically like one year on a one year timeline, let's say, and maybe there's a little bit more of a requirement around making sure you, you know, you have some kind of watchtower or reminder that tells you you need to, you know, do your refresh, but- Potentially in the future, with covenants, that may get better, with some kind of vault or covenant, it may get a bit better. so any, any closing thoughts you wanna finish there with?

Yeah, that, that's great, great feedback and, great conclusion, I think. the only thing I would say is that, yeah, people can use it right now. you know, it's not, you don't need to do anything about the command line or anything like that. You can just download the software, try to

The normal UX, you have to set it up the first time, so you have to have hardware wallets with you and things like that, but people can try it, they can use, Signet as well, which is like one of the test network of Bitcoin. So if you just want to try it and see what it looks like with, with, you know, coins with no value, you can just contact us and we will send you some Signet coins, no problem. and then, yeah, I think that's mainly it. I would like

Launched it and we're going to launch a mainnet very soon. Lianna Lite is a very, very basic version of Lianna, for really people who are using Coinbase today. So it's web-based, so it's really not the same kind of sovereignty, aspect that we were talking about about Lianna Desktop, right? It's web-based, based. You go to liannalite dot com, you plug in your ledger. Currently, it works only with Ledger, but we will add more. and then it, so that's for your main key, then it ask you what recovery key you ho-- you want. So typically your, you know, recovery buddy, your friend that's there, just, you know, to help you out if, if really it, it goes bad. So plug in their ledger or put their xPub there, and then you have a very simple UI, you know, web wallet where it's still your keys, it's your coins, we don't touch the coins, but of course, we are running the backend.

wallet that would connect to whatever server, so we would be able to know, how much money is on this wallet, but we can't spend from it. So this is something we are kind of trying out, and we think that's, that's kind of the, the good first wallet for somebody from your family or whatever, instead of giving them, you know, a, a proper full, self-sovereignty wallet, you just give them, you know, you have this, this is your ledger, only you can spend, but if you lose

Okay, interesting. Oh, yeah, so, yeah, we'll see where it goes. so Kevin, thanks for joining me today.

Yeah, you're welcome. Thank you very much for having me.

I hope you enjoyed the show. Find the show notes at stephanelivera.com. Give us a thumbs up and share it out there with people if you enjoyed it. Thanks, and I'll see you in the citadels.