WEBVTT

1
00:00:00.280 --> 00:00:07.340
You really shouldn't reuse addresses. That's really, really bad. And 10 years ago, that was very common.

2
00:00:07.580 --> 00:00:16.980
Um, now it is not common because wallets will automatically generate a new address every time you pop into the wallet and say, "I wanna receive something." Don't ship hardware wallets to your house.

3
00:00:17.100 --> 00:00:26.580
Never ever, ever, ever do that. Like, that's... And that's, that's hard because, like, not everyone has a PO box, not everyone has a, um, office that they have access to.

4
00:00:26.680 --> 00:00:34.570
If and when these companies have data breaches, you are going to be at the top of the list, and you do not want your home address on there. If you really

5
00:00:35.560 --> 00:00:47.790
want to take the next step towards protecting your Bitcoin privacy, the natural step is to run your own node. You know, you wanna get to a point where that node is actually what is powering your wallet.

6
00:00:47.820 --> 00:00:54.680
It's what your wallet is connected to. You use your node to broadcast your transactions. You use your node to listen to the Bitcoin network.

7
00:00:54.820 --> 00:01:11.460
You use your node to query the blockchain and ask, like, has there been any activity for these addresses that I care about? [upbeat music] Welcome back to Bitcoin Season 2. Privacy is the topic today.

8
00:01:11.500 --> 00:01:24.100
I've got Satshi, who is board of directors for the Payjoin Foundation, a Bitcoin privacy nonprofit. Welcome to Bitcoin Season 2, Satshi. Thanks for cop- coming on. Thanks for having me. I'm excited.

9
00:01:25.280 --> 00:01:35.180
You, uh, made the move to the Payjoin Foundation recently. Can you tell me a bit about yourself and what the foundation does, what you guys are working on right now? Yeah, for sure.

10
00:01:35.280 --> 00:01:45.620
Um, so my background is in both Bitcoin development and education. Prior to Bitcoin, I was a software engineer in just the general space, uh, primarily working in ad tech.

11
00:01:46.200 --> 00:01:52.240
Um, aside from Payjoin, I also work on the Bitcoin Dev project. You can find that at bitcoindevs.xyz.

12
00:01:52.280 --> 00:02:03.500
We do a lot of educational initiatives and create a lot of tooling for developers to kind of take that leap into BOSS, Bitcoin Open Source Software. Um, but I've known the Payjoin guys for a while.

13
00:02:03.540 --> 00:02:12.560
A lot of them are based around the Boston area. We run Boston BitDevs together, and I've been an admirer of Payjoin for quite a while.

14
00:02:12.680 --> 00:02:22.120
I do this-- I have this little project, um, where I make small zines, like little booklets about topics. Um, think I have some right here. Yeah. Showing, I was showing them to the team here- I have like never move...

15
00:02:22.269 --> 00:02:29.940
to describe it. It's a cool little booklet. I've seen one. Yeah. I've actually got one, I think, on my desk back here somewhere. Yeah. Oh, perfect. Yeah. This is not the Payjoin one. This is Silent Payments. Um,

16
00:02:31.140 --> 00:02:33.300
anyways, though. You can find these at satshi.dev.

17
00:02:33.960 --> 00:02:44.340
Um, I did, I did one about Payjoin, and that kind of introduced me to the rest of the team that I didn't know about and, um, into what Payjoin is, which we can get into a little bit later.

18
00:02:44.360 --> 00:02:53.000
But it's basically a batching protocol on the input side, and it has a lot of cost savings, efficiency savings, but also privacy savings as well.

19
00:02:53.560 --> 00:03:07.000
So they just spun up the Payjoin Foundation within the last few weeks, and the idea is to kind of really streamline, um, delivering Payjoin and getting it out there to the world and getting widespread adoption.

20
00:03:07.040 --> 00:03:20.240
And so from a grants perspective, it's much easier for a grants organization to give funds to something like a foundation where the foundation can deploy the mon- the capital, like, most effectively.

21
00:03:20.280 --> 00:03:26.260
They know what developers needed, they know what developers have been working the hardest, what developers need to be recognized.

22
00:03:26.300 --> 00:03:37.640
Whereas, like, that's a lot on the grant organization, especially when you have money coming in from many different orgs, um, and they're not-- they may not always know, like, what, what the other one is up to.

23
00:03:38.280 --> 00:03:48.540
So that's what we're working on. It, it, it just, um, got started. Initial bootstrap funding is coming from OpenSats and Spiral, and we've also been supported by HRF.

24
00:03:48.780 --> 00:03:58.100
Um, so yeah, really, really exciting things to come from the Payjoin side. Yeah. It's 'cause some of the best privacy developers are not necessarily the best at, like, raising money to fund their work.

25
00:03:58.440 --> 00:04:06.520
[laughs] You really need people like you to come and bridge that gap, to speak both dev and, uh, fundraising. For sure. I get it. Okay.

26
00:04:06.620 --> 00:04:18.690
So, uh, for the listener, you know, maybe you stumbled into this through the algorithmically recommended, like, Coindesk feed. Um, so we're gonna lay some groundwork on just general Bitcoin privacy.

27
00:04:19.300 --> 00:04:35.260
Satshi, I'm gonna throw you a few layup questions here just to, like, lay some groundwork, as I said. So there is a general misconception that Bitcoin is anonymous. How private is Bitcoin actually?

28
00:04:35.300 --> 00:04:48.200
You know, you don't have to get into the details, but, like, com- you know, is w- why is Bitcoin not anonymous, and where does it fit? Like, how should you think about it from an anonymity- Yeah... standpoint? Yeah.

29
00:04:48.240 --> 00:04:59.360
Yeah, I kind of just wanna answer that. Yeah. Yes. [laughs] It is pseudo-anonymous. It is not anonymous. Um, and it really depends on how you use it, but for your average user, Bitcoin's not gonna be that private. Okay.

30
00:04:59.420 --> 00:05:10.520
So you're... Let's... M- most people using Bitcoin, I don't know if that's people listening, but, um, they're gonna be going through some kind of exchange or KYC service.

31
00:05:10.580 --> 00:05:20.880
And any time you touch any one of those, you have to give up your ID, your Social Security number, your home address, like all... Like, a selfie, all this information.

32
00:05:20.980 --> 00:05:33.200
Um, and so yeah, plenty of, like, public figures like to say that Bitcoin is money for criminals, but the truth of the matter is that it's, it's quite easy to, to trace these things. Um, it...

33
00:05:33.340 --> 00:05:43.340
The blockchain is public for anyone to go and look at and see where money... Uh, if, if you, like, know the... If you know something about one address, you can follow it.

34
00:05:43.400 --> 00:05:46.780
You can see, like, where the money came from before it was at that address, where it's going afterwards.

35
00:05:47.240 --> 00:05:58.740
And so a lot of the responsibility falls upon the user to kind of make sure that they're using Bitcoin in a way that accommodates their own personal threat model, and there's lots of different ways to do that.

36
00:05:58.780 --> 00:06:13.836
There's lots, lots of different levels. But, um-Bitcoin's probably not as private as most people think it is, by default And you, and yet you say privacy in Bitcoin is possible, but it's hard. What do you mean by that?

37
00:06:13.876 --> 00:06:22.596
Yeah. There's a lot of, um, precautions that, that... Well, like, things that you can take to protect yourself and reclaim your privacy. I think privacy in general is really hard.

38
00:06:22.636 --> 00:06:26.316
We can probably look at it through the lens of just your digital privacy, period.

39
00:06:26.376 --> 00:06:38.346
Like, a lot of the best practices that you hear about how you should operate on the internet apply to Bitcoin because Bitcoin is internet money. Um, your, your web browsing, are you using a VPN? Are you using Tor? Um,

40
00:06:39.296 --> 00:06:41.716
the, the email service provider that you use.

41
00:06:41.826 --> 00:06:55.476
Um, but there are like, there are certain things that we're, we're trying to, to raise it, and part, this is part of what Payjoin's trying to do, that, like, default minimum level of privacy that you would get as an average Bitcoin user.

42
00:06:55.556 --> 00:07:04.816
So an example is you really shouldn't reuse addresses. That's really, really bad, and 10 years ago, that was very common.

43
00:07:04.916 --> 00:07:12.296
Um, now it is not common because wallets will automatically generate a new address every time you pop into the wallet and say, "I wanna receive something."

44
00:07:12.376 --> 00:07:18.746
However, the [laughs] the tricky thing about Bitcoin is, like, the more you know, the more dangerous you become to yourself.

45
00:07:18.846 --> 00:07:28.896
And so let's say you understand Bitcoin a little bit, and you're like, "Oh, well, I'm just gonna like... I, I have this address. It works." Like, you can just keep depositing money to that, like, that's fine.

46
00:07:29.136 --> 00:07:39.096
Um, the problem with that is, like, because Bitcoin follows that UTXO, u- unspent transaction output model, everything's like a coin. It's, it's a unit of a different denomination of Bitcoin.

47
00:07:39.376 --> 00:07:48.876
And then once you, like, mix these coins together, like, that's, that's not good. Um, but, but, like, optimistically, like, that's not too much of a problem today for most people.

48
00:07:48.996 --> 00:07:58.306
So, um, yeah, in, in general, kind of the things that you wanna do are very similar to precautions you would take to protect your privacy on the internet already.

49
00:07:58.856 --> 00:08:12.796
And let's dive into a couple of these, 'cause you suggested there's, like, a number of things that the average person can do which aren't huge lift, which just are just almost, like, I would say, basic Bitcoin privacy techniques.

50
00:08:13.336 --> 00:08:24.556
Um, you said address reuse, uh, uh, um, passing messa- uh, you know, addresses back and forth, hardware wallets. Which of these do you think you wanna kinda, like, tackle? Yeah.

51
00:08:24.616 --> 00:08:37.316
So I think a lot of these are probably obvious if you think about them, but I don't know, Pa- or, u- the internet and, like, digital security is sometimes a space where we think something's a good idea, but we don't do it unless someone else tells us.

52
00:08:37.356 --> 00:08:51.485
Like, one example is if you need to, if I, if I wanna, like, send you some money, and I ask you for an on-chain address or a Lightning invoice, like, don't send that to me in plain text over just any communication medium.

53
00:08:51.596 --> 00:09:00.716
Use something encrypted. Same goes for, like, when I pay you, and I'm gonna give you the transaction ID. I'm gonna use Signal to give that to you because, like, you just don't wanna be leaving breadcrumbs everywhere.

54
00:09:00.816 --> 00:09:12.316
And another really big thing is don't ship hardware wallets to your house. Never ever, ever, ever do that. That's, like, that's... And that's, that's hard because, like, not everyone has a PO box.

55
00:09:12.356 --> 00:09:23.676
Not everyone has a, um, office that they have access to, um, you know. And, and maybe if you're renting, especially in a big apartment complex, eh, okay, fine.

56
00:09:23.696 --> 00:09:33.276
But, like, if and when these companies have data breaches, you are going to be at the top of the list, and you do not want your home address on there because they will come after you.

57
00:09:33.816 --> 00:09:44.376
I, I know, like, my name has been on data breaches, and it, not a lot of information has been there, and I've just been like, you know, harassed with all the scam calls, and, like- Yeah... you just, you don't want that.

58
00:09:45.076 --> 00:09:54.056
Um, so it's stuff like that that, um, or again, like using a VPN, ad blocker. Those- Yeah... those are some of, like, the really easy things that you can do.

59
00:09:54.436 --> 00:09:57.696
Yeah, like the harder thing, and I'll, I'll pick on them 'cause I, I, I like them.

60
00:09:57.736 --> 00:10:07.306
Like Ledger had a hack a few years ago, and I mean, I, I guess it was like 2019, which is a while ago now, but yeah, I could see everybody in my hometown who bought one of these- Mm-hmm...

61
00:10:07.316 --> 00:10:09.696
and I have their address and their name.

62
00:10:09.786 --> 00:10:20.666
And I'm not a bad actor, but y- you know, just from subjective experience, like, I'm now bombarded by all sorts of, uh, inquiries, even though I don't even have that address anymore. Mm-hmm.

63
00:10:20.676 --> 00:10:32.146
It's, it's ancient history now, and so, uh, yeah, it's, it's, you know, it's, it does... Y- you can assume, like, anything you buy and ship to your address is gonna- Yeah...

64
00:10:32.216 --> 00:10:43.656
somewhere, that information's gonna get out eventually. Yeah, yeah. And, and same goes for email. If, if it's possible, generate a unique email that's not tied to your personal government [laughs] identity. Um,

65
00:10:45.056 --> 00:10:50.956
yeah, it's, it's, it's, it's, it sucks 'cause it's, like, more work, but you'll thank yourself in the long run. Yeah.

66
00:10:51.536 --> 00:11:00.756
Um, there are some kinda weird things, like, you know, running a VPN is not necessarily, uh, I would say that's not necessarily something that you'd need, that, uh...

67
00:11:01.196 --> 00:11:12.396
Like, that's not a, that's not the same thing as, like, uh, op- interacting with the Bitcoin network. That's like, like a- Yeah... secondary action on top of- Yep... uh, you know, interacting with Bitcoin.

68
00:11:12.496 --> 00:11:15.366
Can you, can you explain this a little bit more for me? Yeah.

69
00:11:15.456 --> 00:11:26.016
Um, well, that's gonna protect your internet privacy, and one thing that comes to mind is we often use public block explorers to look up addresses we care about, transactions we care about.

70
00:11:26.636 --> 00:11:31.476
If you're a dev [laughs] you're probably looking a lot more than that. But, um, that will protect your IP.

71
00:11:31.636 --> 00:11:44.155
And so the, uh, anyone kind of snooping or anyone even on the server side, they're not gonna be able to say, "Wow, this IP really cares about this cluster of addresses. I should pay attention to that."

72
00:11:44.796 --> 00:11:57.016
Um, so and, and that also just comes from, we can talk about this later, but, like, um, if you're not running your own node, you have to rely on another party to get you information about the blockchain.

73
00:11:57.436 --> 00:12:05.936
Well, let's go into that, the concept of running a node. Everybody's ta- arguing about node running right now. Yeah. [laughs] Um, so we're not gonna argue about that.

74
00:12:06.076 --> 00:12:16.828
Uh, privacy is a very compelling reason to run your own nodeUm, dive into this for me. Kind of explain how this works and why the privacy conscious- Yeah... would wanna do this.

75
00:12:17.348 --> 00:12:21.908
Yeah, I feel like we're never gonna get away from this topic ever [laughs] as a community.

76
00:12:22.548 --> 00:12:29.508
Um, luckily, I think, like, the technical solutions still keep chugging along and, and make it a little bit easier, but if you really

77
00:12:30.488 --> 00:12:43.957
want to take the next step towards protecting your Bitcoin privacy, the natural step is to run your own node and connect... Well, okay, you can run your node, and you can use it to back, um, a block explorer.

78
00:12:44.088 --> 00:12:54.118
You can use it to just look up your balances, like, if you're handy with the commands line. Um, but, you know, you wanna get to a point where that node is actually what is powering your wallet.

79
00:12:54.148 --> 00:13:01.188
It's what your wallet is connect to. You use your node to broadcast your transactions. You use n- your node to listen to the Bitcoin network.

80
00:13:01.648 --> 00:13:11.908
You use your node, which, you know, may have an Electrum server in front of it, to query the blockchain and ask, like, has there been any activity for these addresses that I care about? That's hard.

81
00:13:12.488 --> 00:13:25.258
Um, there are some reasons to be optimistic about that, that get me really excited. Um, one example is a project called Kyoto by Rustation Rob. No surprise, it's in Rust. Yeah.

82
00:13:25.268 --> 00:13:31.848
And kind of one of the exciting things about that is because it's in Rust, it's gonna be easier for other wallets written in Rust to integrate it.

83
00:13:31.968 --> 00:13:40.598
But it's basically a light client that is a happy medium between, like a, like a trade-off between running your own node and trusting a third party completely.

84
00:13:41.098 --> 00:13:49.788
Um, another thing that I don't-- I mean, this is, this is long work, so we don't always talk about it, um, but initial block download time.

85
00:13:49.908 --> 00:13:59.288
So when you start up a Bitcoin Core node, the first thing you have to do is actually download the whole blockchain from your peers, and that takes, I think, a couple of days. It really depends on, like, your hardware.

86
00:13:59.348 --> 00:14:04.368
Like, if you're running a Raspberry Pi, know that's [laughs] gonna take a lot longer than that. Um, or if you've got nice hardware, it'll, it'll take faster.

87
00:14:04.608 --> 00:14:12.188
Um, but there are so many projects out there that are working towards speeding this up because, in general, this is just a great development for every single node runner.

88
00:14:12.308 --> 00:14:28.908
So we've got UTXO where instead of holding the UTXO set in memory, you're, you're just looking at a Merkle tree of references to UTXOs, and if you wanna spend something, you just provide a ref-- or you provide the proof of the UTXO that it's in the Merkle tree and that it's unspent.

89
00:14:29.318 --> 00:14:36.868
There is SwiftSync, um, just this past spring was proposed where instead of downloading, um, getting it confusing... Oh, no.

90
00:14:37.148 --> 00:14:50.048
Yeah, instead of when, when you're doing the IBD, um, if you get a UTXO, you get kind of this, like, block hint that tells you, does this UTXO appear in the final UTXO set that I will have when I'm done syncing the blockchain?

91
00:14:50.488 --> 00:14:59.588
And if it's not, just don't put it in there. Um, and then s- somewhat similarly is Assume UTXO with some snapshots. The guys at ZeroSync are doing some stuff with headers and zk-SNARKs.

92
00:14:59.598 --> 00:15:13.848
Like, there's a lot of reasons to be optimistic about this idea that we can run nodes in a way that sufficiently powers wallets to protect our privacy but also enhance our financial self-sovereignty.

93
00:15:13.858 --> 00:15:25.927
And that gets us really close to, I, you know, it's not the holy grail, but it's, it's almost like the, you know, the bronze grail of, like, running a node on your phone. Oh, yes. And it's-- yeah.

94
00:15:25.968 --> 00:15:29.698
It's not the solution, but, like, that, that kind of thing would dramatically open up- Mm-hmm...

95
00:15:29.878 --> 00:15:48.508
the design space for application developers, users to just do this because, you know, I'm-- this is a bit of a layup here, but, like, you know, when I download, say, a popular application like BlueWallet and I, on my phone, and I'm not connecting to my node, whose node am I connecting to, Satsy?

96
00:15:49.048 --> 00:15:54.168
BlueWallet's node. [laughs] Yeah. Thanks for asking. [laughs] Yeah, BlueWallet, BlueWallet's...

97
00:15:54.198 --> 00:16:04.028
See, well, okay, it's, it's, I don't know everything about how BlueWallet works, but, um, mo- if you're not connecting your wallet to your own node, you're using the wallet provider's node.

98
00:16:04.048 --> 00:16:13.628
And the wallet provider's node, even if you signed up with a pseudonymous email, okay, and using, like, a VPN, but, like, they still know your balances. They still know your addresses.

99
00:16:13.668 --> 00:16:23.088
They still know your transactions because how in the world are you gonna broadcast your transaction without going through their node? So I love that you brought up, um, nodes and phones.

100
00:16:23.268 --> 00:16:30.748
I think, I think we will get there one day. I do feel like, um, I don't know if it was, like, or something. I feel like I was at a conference, and they were like, "We, we did it.

101
00:16:30.848 --> 00:16:38.828
We figured out how to put a node in the phone," and I don't know what happened to that because I don't think they actually figured it out. [laughs] I actually do remember this era. I was at a conference.

102
00:16:38.868 --> 00:16:47.718
I remember I was at Bitcoin Park, and someone, like, showed me. I got full node on my phone. I was like, "That's awesome." I've not heard anything about it since then. [laughs] Oh, no. It just disappeared.

103
00:16:47.948 --> 00:16:59.828
[laughs] They got, they got 'em. Uh- Yeah. Yeah. [upbeat music] Hey, Will here with Blockspace Media. Did you know that we have individual feeds for all our shows?

104
00:17:00.128 --> 00:17:11.068
If you're watching the Mining Pod, Bitcoin Season 2, or the Court Show, be sure to check out the individual feeds. You can find them on your podcast player of choice, whether that be Spotify, Apple, YouTube, et cetera.

105
00:17:11.608 --> 00:17:17.988
Just type in Blockspace Media, and you'll find all our shows pop up. Or just type in the individual show name, like the Mining Pod or Bitcoin Season 2.

106
00:17:18.248 --> 00:17:33.188
Be sure to hit that subscribe and give us a five-star rating so we can continue to bring you the best content in Bitcoin. [upbeat music] One of the more interesting things are, uh, the ways you can obscure

107
00:17:34.168 --> 00:17:51.228
your transactions through a variety of methods. But one, uh, and, um, uh, is by pay joining. I'm not sure the nomenclature you use, um, is to, to pay join your transactions.

108
00:17:52.808 --> 00:18:02.468
What is a pay join? Yeah. How does it work? We could probably do a few cycles on this. Okay, great. Yeah, so a pay join, um, it is the essential...

109
00:18:02.688 --> 00:18:13.668
So when we talk about transaction batching, we're trip- typically familiar with the batching on the output side. Let's say an exchange has five people requesting, um, money to be sent to them.

110
00:18:14.228 --> 00:18:25.324
Instead of making five different transactions, they're gonna make one transaction with five different outputs to each of those individuals. Pay joinBasically does that on the input side.

111
00:18:25.604 --> 00:18:41.484
Um, so one example is if I, if I want you to send me money, um, what I'm gonna do is give you an address, and you're gonna create a partially signed Bitcoin transaction, a PSBT, and you're gonna give it to me.

112
00:18:41.504 --> 00:18:49.864
And what I'm actually gonna do is I'm gonna add an input of my own to that. And this accomplishes a few things.

113
00:18:49.964 --> 00:18:56.724
Um, for one, it's actually really ni- I can, um, for this example, I'm not gonna change any of the outputs, but I, I can control what the outputs are.

114
00:18:57.344 --> 00:19:08.404
Um, I basically am doing a coin consolidation though, because like in a normal transaction, you send me, let's say, one Bitcoin, and then I have one Bitcoin, which is an extra UTXO in my wallet.

115
00:19:08.984 --> 00:19:17.824
But if you send me one Bitcoin and in that transaction I add an additional endpoint for, input for another Bitcoin, so now I'm just left with two Bitcoin when it pops out.

116
00:19:18.424 --> 00:19:27.204
Um, so that, it, there's like nominal fees added to that, so there's real benefit for the receiver. Um, but that's, that's the general idea of how it works.

117
00:19:27.243 --> 00:19:35.104
You just, the, the receiver is adding another input and it has some, some really interesting priva- privacy bene- fits as well.

118
00:19:35.284 --> 00:19:40.544
It breaks the common input ownership heuristic, which we see in the original Bitcoin whitepaper.

119
00:19:41.124 --> 00:19:52.794
Basically, even Satoshi has said it, um, when we see a transaction, we can pretty much assume that all the inputs belong to the sender. With PayJoin in its current state, that is no longer true.

120
00:19:53.184 --> 00:20:02.684
The inputs could belong all to the sender or some could belong to the receiver, and we don't know which ones do. So, you know, when would I be using PayJoin?

121
00:20:02.724 --> 00:20:18.564
Is this a niche case for only the transactions I want to be pseudonymous? Uh, or is this something that is a low lift to proliferate across like the entire Bitcoin ecosystem? Like- Yeah...

122
00:20:18.604 --> 00:20:30.304
you know, contextualize this for me. We, we want everyone using PayJoin all the time [laughs]. I mean, most of it is actually automated. Um, the wallets are able to handle kind of the passing back and forth of the PSBT.

123
00:20:30.644 --> 00:20:38.304
It relies on the assumption that you're some- you're online sometimes all the time, um, whereas previous versions of PayJoin, you had to be online all the time.

124
00:20:38.424 --> 00:20:49.664
But the, the beautiful thing about it is the more people that use it, the more it benefits all of us. I'm very hesitant to put a number on the amount of the network that we need using PayJoin.

125
00:20:49.804 --> 00:20:57.524
I've heard 5% thrown around because it's statistically significant. I'm not a data scientist [laughs], I can't speak too much to that.

126
00:20:58.004 --> 00:21:10.224
Um, but if we are able to get enough people using PayJoin, then that common input ownership heuristic is no longer useful to a chain analysis firm. And, and so we all stand to benefit from it.

127
00:21:10.804 --> 00:21:19.824
So it's one of those things which has significant network effects, and you say that it's very dependent upon what the, whether the wallet software facilitates this.

128
00:21:20.284 --> 00:21:27.424
You know, I had, um, I had Seth from Privacy on a few months ago. He's with, with Cake Wallet. Shout out Seth and Cake. Um,

129
00:21:28.324 --> 00:21:35.164
like where would you say we are on the like adoption curve of PayJoin and wallets that facilitate this and yeah. Yeah.

130
00:21:35.644 --> 00:21:44.594
I think we're at a really exciting time, and I'm not just saying that because I just joined the board. I think, um, well, Cake Wallet obviously supports it. Bull Bitcoin, the exchange supports it.

131
00:21:44.624 --> 00:21:57.624
Exchanges have so much to gain from PayJoin too because of those, um, fee savings that they get, and there's also something called transaction cut-through, which is basically when you kind of use a transaction for multiple purposes.

132
00:21:57.664 --> 00:22:02.424
And one of the things that really attracted me to PayJoin is that it's an on-chain solution for scaling.

133
00:22:02.544 --> 00:22:08.544
So let's say you have an exchange that needs to pay out some money to people, but they also have people depositing in.

134
00:22:08.924 --> 00:22:18.664
What they can do is take the transaction that's bringing in the deposits and then just edit it so that the deposits go straight through to the people they need to pay out to anyways.

135
00:22:18.744 --> 00:22:28.164
So, um, as far as PayJoin goes, the, the, the top priority right now for the team is working on integrations. Um, I don't know the full list.

136
00:22:28.244 --> 00:22:37.464
The full list is on payjoin.org, but, um, BlueWallet, Sparrow, I think Liana's coming down the way. Uh, Cake Wallet is a big one. Cake Wallet also supports silent payments.

137
00:22:38.224 --> 00:22:49.174
Um, BTCPay Server, JoinMarket, all those things support PayJoin, and there are many more integrations to come in the future as well. Yeah, those are like the Avengers of like privacy- Yeah [laughs]...

138
00:22:49.174 --> 00:23:02.964
[laughs] on Bitcoin. Yes [laughs]. Um, you mentioned before we hit record this, uh, concept called multi-party PayJoin. Yeah. I don't know if you wanna like explain a bit what that is. Yeah. Uh, go. Yeah, for sure.

139
00:23:03.044 --> 00:23:16.124
So when you think about like a normal PayJoin between two parties, like if we're doing one together, you and I actually know, like I know what inputs were mine and you know what inputs were yours, and we know what outputs each other have.

140
00:23:16.284 --> 00:23:24.124
So there's like some privacy lost in that regard, um, even though we are pretty well protected against your average person just looking at the blockchain.

141
00:23:24.504 --> 00:23:35.974
What multi-party PayJoin does is it just introduces more par- parties into the equation so that you can kind of have multiple people contributing inputs and taking out outputs and, uh, it's some exciting stuff.

142
00:23:36.064 --> 00:23:45.444
I believe they have it in experimental mode right now in, which I forgot to mention earlier, the PayJoin dev kit, that's kind of like the, the artifact that the PayJoin Foundation produces.

143
00:23:45.524 --> 00:23:57.424
It's a, a library for devs, mainly in Rust, um, but there are also, I think, options for Python, Kotlin, um, and other bindings available as well. You know, you also threw out a term, uh, silent payments.

144
00:23:57.884 --> 00:24:09.804
Uh, Seth did kind of explain this a few months ago, but, uh, this is another tool in our privacy arsenal. What's a silent- Yeah... payment? Yeah. Oh, gosh.

145
00:24:10.144 --> 00:24:17.574
This, this one gets me excited too because, um, I think a lot of people want to have... Uh, and lightning addresses kind of solve this.

146
00:24:17.724 --> 00:24:28.708
Um, but basically if you are, say you wanna collect donations for the podcast, um, and you just wanna post an addressUm, you can do that, but we learned earlier that address reuse is very, very bad.

147
00:24:28.988 --> 00:24:38.968
Um, especially like just-- I just wanna mention like, as we think forward to like post-quantum computing days, like you do not want to have used-- reused addresses, like, [chuckles] that you're gonna regret that.

148
00:24:39.448 --> 00:24:47.908
Um, but basically, silent payments allows you to get the same user experience as address reuse without actually reusing addresses.

149
00:24:47.988 --> 00:25:01.648
So the way it works is you will create, I think it's technically two public-private key pairs. You'll combine the public ones to create what we call a silent payment address. Um, it starts with the letters SP one.

150
00:25:01.868 --> 00:25:11.848
It kind of looks like a Bitcoin address for that reason, but it is not recognized by, um, the network. Like, you're not gonna be able to plug that into a block explorer.

151
00:25:11.888 --> 00:25:26.488
But when somebody wants to pay you, they take your silent payment address, and they actually combine it with the private key from an input that they want to send to you because every UTXO has a set of keys associated with it.

152
00:25:26.528 --> 00:25:37.448
And so they-- in doing so, they're actually able to derive a unique Taproot address for you, which is, like, so wild to me, um, the fact that they're able to do that.

153
00:25:37.528 --> 00:25:40.348
That's, that's an on-chain address and that they send funds to.

154
00:25:40.448 --> 00:25:59.908
Um, the, the trade-off is for the receiver, they actually have to scan the blockchain and look at every single transaction in every block and every UTXO and every transaction and compute, like, what would the address have been if this person was sending this UTXO to me.

155
00:25:59.948 --> 00:26:13.088
And if any of them match, then they, they found it. Um, there are... I, I think like in principle, that sounds like a lot, um, but I, I think that is a technical challenge that can be overcome.

156
00:26:13.108 --> 00:26:17.568
But I think that's why you don't see too much like silence to payment, payment support at the moment.

157
00:26:17.628 --> 00:26:28.208
It's just, it's a really hard engineering problem, but I don't think it's impossible, and I'm really optimistic for a future with silent payments because I think that is just a very useful thing for, for everyone to have.

158
00:26:28.268 --> 00:26:32.628
You don't need to be online. You can just have this address up and, and people can donate to it. Yeah.

159
00:26:32.808 --> 00:26:52.228
It's interesting because it seems that there are s-- there are several very clear directions for engineers to run and to, like, improve privacy on-chain, uh, and a lot of them relate to very obscure technical things such as indexing Bitcoin, local computation, stuff like that.

160
00:26:53.108 --> 00:27:04.848
You know, if we're gonna-- I wanna zoom out really wide and look at where you and I exist in the United States and reflect on, you know, you don't have to be an expert on, on

161
00:27:05.848 --> 00:27:16.748
each of the, you know, the, the various, like, open source developer, uh, leg-- trials or legal issues or, you know, privacy constraints happening.

162
00:27:17.188 --> 00:27:25.808
But, like, what is your evaluation of what the current, like, um, what the current momen- uh, momentum for pr- behi- uh, for privacy?

163
00:27:25.948 --> 00:27:42.368
Where, where do you think the current direction of privacy is from a regulatory standpoint in just the United States narrowly? Um, it's-- it doesn't feel awesome, especially coming out of the previous administration.

164
00:27:43.108 --> 00:27:53.568
I think this new one is giving us a little bit more breathing room to continue to develop these technologies that protect our fundamental right to privacy.

165
00:27:53.588 --> 00:28:04.288
But I don't think anyone is going to breathe easy until we get some actual legislation that, like, on paper will reflect,

166
00:28:05.328 --> 00:28:12.358
like, the protections of the developers, and even it's less talked about, but the people running the infrastructure for, for some of these things. I know there's like,

167
00:28:13.268 --> 00:28:23.497
we're all hoping the Clarity Act will pass, um, which protects non-custodial wallet developers and, and people working on those things. That would be really good.

168
00:28:23.548 --> 00:28:35.747
And, and yeah, no matter how many like feel-good memos we get out of the administration or Department of Justice, like that's not, that's not gonna make me feel better [chuckles] until we actually have legislation.

169
00:28:35.888 --> 00:28:47.498
So I'm gonna throw a curveball at you. There's a lot of software proposals out there. Um, they can be spicy, they can be controversial, but there are some leading, there are some leading ones.

170
00:28:47.528 --> 00:28:59.708
There's CTV, CheckSigFromStack, there's CAT, there's things which enable L, you know, L two or Lightning Symmetry. Some of these have various privacy, privacy improvements. They would require coordination.

171
00:29:00.568 --> 00:29:13.548
Do you have any thoughts around any, any specific proposals or, um, I guess, what do you think of soft forks in general as avenues that we should, uh, pursue to improve on-chain privacy?

172
00:29:13.988 --> 00:29:24.078
So this is actually definitely a blind spot for me, so I will hand it to you for the curveball. Okay. [chuckles] Um, I... In general, soft forks are very-- they're obviously very contentious.

173
00:29:24.148 --> 00:29:27.548
They're intimidating because you can't really reverse them.

174
00:29:28.208 --> 00:29:38.288
Um, I, I, I don't personally have experience comparing the s- the different, um, soft fork proposals, and this is probably gonna be the impetus for me to go home. Well, I am home right now.

175
00:29:38.348 --> 00:29:43.268
But like to actually do my research, and I think it's long past time that I develop a stance on these.

176
00:29:43.488 --> 00:29:59.688
Um, but yeah, in general, I mean, there's also like that social aspect where it becomes like kinda scary to talk or support certain s-soft forks just because the Bitcoin social community network, whatever you wanna call it, like, um, the immune system is so very strong.

177
00:29:59.718 --> 00:30:11.608
And I didn't expect to see ordinals come out of, um, honestly, wasn't that SegWit that really enabled them, not necessarily- Yeah... Taproot. Um- Yeah...

178
00:30:11.648 --> 00:30:19.688
so we, yeah, we, we don't-- no matter like how well vetted a, a code change is and how many people that you respect that are behind it,

179
00:30:20.808 --> 00:30:27.968
I still like lots of things can happen that you would never expect, and nobody kinda wants to be responsible for that.

180
00:30:28.408 --> 00:30:35.088
I think we need to have a lot more grace with each other when we're talking about these things, though I know-- like I understand people really, really care. I, I care deeply as well.

181
00:30:35.348 --> 00:30:44.746
Um, but we are all, uh, people, and I thinkWe can, we can, we can talk about this nicely. [laughs] Yeah, many such cases. I, I, I know.

182
00:30:44.876 --> 00:30:51.256
I always like to throw it out because I don't think many people are just forward asking about it. Um- Mm-hmm. They... Yeah.

183
00:30:51.876 --> 00:30:58.176
I feel like the conversation has kind of been overtaken by other things that have been happening in this space as of late. Yeah.

184
00:30:58.556 --> 00:31:08.136
So, um, I think this has been a pretty good, like, primer on how, uh, the average person can think about privacy and where to go. I would say let's, let's wrap this up.

185
00:31:08.496 --> 00:31:21.356
Point the listener in a direction to learn more and to follow along with what particularly you and the Payjoin Foundation are working on, but just where do you think people can follow the privacy story of Bitcoin the best?

186
00:31:21.676 --> 00:31:35.316
Oh, um, actually, [laughs] in preparing for this podcast, I looked at the Bitcoin wiki, and that had a lot of really good stuff, and it was up to date. [laughs] And I just...

187
00:31:35.716 --> 00:31:43.116
Reading through that was actually really helpful. One of my favorite resources is Bitcoin Optech. I- That may be kind of technical, but you can even...

188
00:31:43.156 --> 00:31:50.796
Like, like, if you find the recaps and the newsletter a little above you, um, I also think it's really great just for looking up a topic that you wanna know more about.

189
00:31:50.876 --> 00:32:01.926
It is maintained by some of the best engineers in this space. Um, they really... A- and talented technical writers. Um, I also work on...

190
00:32:02.576 --> 00:32:16.056
Well, I work on the Bitcoin-dev project, and we have a project called, um, ChatBTC, which is like ChatGPT, but it's trained on specific, like, high-signal sources like the Stack Exchange, like the mailing list, like DelvingBitcoin.

191
00:32:16.136 --> 00:32:25.936
DelvingBitcoin is another good one. Um, yeah, it's ki- it's kinda hard to find the signal over all of the noise though, especially if you haven't been paying attention for a while.

192
00:32:26.016 --> 00:32:41.216
Um, as far as Payjoin goes, payjoin.org is gonna give you all the information about Payjoin as a protocol, but you can also go to payjoindevkit.org, which will help you, um, understand how, what it's gonna take to integrate Payjoin into a wallet.

193
00:32:41.856 --> 00:32:55.056
If you want-- If you use a wallet and you want Payjoin in there, tell your wallet, um, and tell the Payjoin dev team. Uh, all else, like, there's a Discord, um, for Payjoin that you can find in the Payjoin website.

194
00:32:55.316 --> 00:33:03.336
Um, you can even, like, file a GitHub issue if you just, like, don't know where to start. So tho- those would be the resources that I'd recommend. Yeah.

195
00:33:03.356 --> 00:33:15.396
So for the listener, if you have a, a Bitcoin wallet that you like, hit them up, reach out to the contact, tell them you want to integrate Payjoin and/or Silent Payments or these other privacy things.

196
00:33:15.456 --> 00:33:25.296
So Sassy, thank you so much for coming on Bitcoin Season Two. I really enjoyed this. Maybe we'll do another privacy conversation down the road. Um, but otherwise, thank you so much. Cheers. Thanks, Greg. That's great.

197
00:33:25.316 --> 00:33:38.846
[laughs] Thanks for having me. [outro music]
