Loading summary
A
I think I got kind of orange pilled and privacy pilled in this way. When Snowden exposed all this surveillance that was happening by default through every system you've ever touched, that's when I started treating all digital infrastructure as inherently recording devices. Like they're trying to take information and then even if someone doesn't really want or intend to store the information, like it's possible that it gets leaked through a hack. And when it comes to money that reveals all the relationships someone has and without privacy, there's no way for that to be free. And for Bitcoin to kind of live up in my mind to what it was meant to do, be censorship resistant, you need to have privacy.
B
What is up guys? Welcome back to Bitcoin Audible. I am Guy Swan, the guy who has read more about Bitcoin than anybody else. You know, we have got Dan Gould on the show today and this was a fantastic, this was such a good conversation and there is something very elegant and like something that I deeply appreciate about finding the simplest way to do something in kind of an automatic. And it can be implemented everywhere and people wouldn't even notice sort of way of just like making the thing work to get the first piece of a much bigger picture. And this is one of those tools. If you've ever heard of Pay join. You know, Dan actually get to talk to him about, you know, a lot of the origins and what he worked on and where he started in privacy because he actually kind of started on this and was going in this direction way back in 2017 and 2018 and started with, you know, working with Tumblebit or interested in Tumblebit and, and the original Pay joins and how BTC Pay implemented it and all of these things. And we kind of get into why it didn't work or what the trade offs were or why it could or could not be universal and what actually needed to be solved. Like what was that missing piece that they're tackling now with a ton of contributors. Right. Like Dan is just on the show to talk about his, his piece of it and the project at large because they're at a really, a really amazing pivot point and so it's like perfect timing to like really dig into it. A shout out to him. Don't forget I'll have links and stuff in the show notes so you can follow and check all this stuff out. A shout out also to our sponsor to Bitbox and the Bitbox 02 Nova everybody. You guys know I love the Bitbox hardware wallet. I have like three of them or four of them, I don't know. And I also have little crypto cloak cases. They're so cool and I have like little. They're like color coded and stuff. I love, I love my bitboxes but if you are not holding your own keys, you need to be. Bitbox is just an unbelievably easy. And speaking of elegant and simple ways to do something, of just solving a problem, I really just think it's one of the best. Integrate into your own stuff. Use their software, use their hardware wallet like start to finish a simple setup to just holding your own keys, you know, and do so securely and safely. And it's just a. It's just a solid all in one package. And in addition you can get all of the complexity and cipher punk stuff and custom setup if you want but you don't need it if that's not your thing. And, and I know this because I have some that are just set up normally and then some that are set up, you know, connected to my own node and, and I have like a bunch of different pieces of it in multisig and all this stuff. So check it out if you haven't. And I got a discount code and it's also a really, really great way to support the show to let them know that I sent you and you get to hold your own keys. You get to be like a solid true bitcoiner. So support the show and hold your own keys. Win win. So check them out details. All the stuff is right down in the description of this episode. And with that, let's get into today's chat. This is all about pay join. The time has come for privacy on Bitcoin with Dan Gould. Dan, welcome to the show. Welcome to Bitcoin Audible man. Good to have you guy.
A
Thanks for having me. Thanks for the invite.
B
Yeah, yeah. So we got. We got a lot to get into. I got you on just because I was reading about and really want. I actually have not read dug into Pageoin v3. I'm not even. I don't even think I've used Pageoin except maybe once because I had it like turned on and BTC pay. I want to say like it occurred with a transaction. I remember, I remember thinking there was something funny about it but I don't know if it's even automatic or how it works. But I've always loved the idea. It's just not something that, that I've ever managed to come into contact to, you know, like, like just kind of had available like if somebody ever Was just like, if I was at a merchant and I like scanned and somebody was like, do you want to pay join? I'd be like, oh hell yeah. I hit the button, you know, but integration just kind of in my circles is it always just end up being lightning. Right. So I, I wanted to kind of dig into that in UX and all that stuff. But also just like, where is it? Like what's the state of it? What are the new things? You've got dev kit on the way. And let's start with your background because I don't know much about you either. What kind of led you to what you're doing with privacy and also why are you working on privacy? Why are you building these things in particular? Why is it important to you?
A
Why is privacy important to me? I'll definitely get there. But I do want to touch on one thing you already said, which is like that your experience with Patron was automatic and in the background. And that's kind of the whole point that I want.
B
That's the dream, right?
A
You shouldn't even need a button to come up and say it happens. It's just when you're using Bitcoin settlement, it's done by default on the base layer. Which also kind of gets me into why I'm working on this, where it started. Like I have been working on the Bitcoin privacy problem for at least it's 2018, I think.
B
Oh, wow. Okay.
A
Yeah. Following along with like C Land, what the BTC pay guys were doing, what the Wasabi guys were doing, and incrementally coming to the understanding that, okay, the only we need Bitcoin privacy to be solved in this automated way at the base layer you can build a bunch of stuff at higher layers, but if it's not at the base layer, you're always going to have leaks. And I saw everyone doing this through applications. So like download this privacy wallet and take this privacy action and get privacy. Which leaves everyone that doesn't make that their priority, you know, seconds to that. They don't, they don't have that. So the approach, yeah, I just came, came to this place that it needs to be automatic. I, I think I got kind of orange pilled and privacy pilled in this way. When Snowden exposed all this surveillance that was happening by default through every system you've ever touched, that's when I started treating all digital infrastructure as inherently recording devices. Like they're, they're trying to take information and then even if someone doesn't really want or intend to store the information, like, it's. It's possible that it gets leaked through a hack. And when it comes to money, that reveals all the relationships someone has, and without privacy, there's no way for that to be free. And for bitcoin to kind of live up in my mind to what it was meant to do, be censorship resistant, you need to have privacy. Satoshi even let us left us some breadcrumbs there. We can get into that. And Snowden has tweeted about this, even kind of clashing with Gladstein on Twitter, which I think is kind of funny about how, like, oh, we still don't have privacy despite all the advances. And it's just a huge problem. There's a lot to be done, and I feel like nobody, at least when I started, was taking this problem first approach. So it was a big opportunity, and now it's just become kind of part of who I am. I'm. I'm stubborn and very interested in seeing the state of the art advance.
B
Stubborn's the best. Stubborn's the best. Especially when you're stubborn about something you want to see in the world. Like, stubborn is how. As how those things actually arrive. No, I totally agree. Especially in the whole, like, it has to be automatic thing because your, you know, your anonymity set is the thing that makes privacy work, right? Especially when you're talking about something like a public network and, and, you know, the nature of bitcoin. And this is why something like taproot and cross input, signature aggregation, like all these, like, supposed proposals that the intent was for them to be, you know, widely used, were seemed very important to that conversation to me in the past and probably still are, but that you can actually make it economically efficient. You know, privacy has always been a cost. It's always been like something that you had to care enough about to go do, you know, to go get signal or crypto chat or like, you had to go get another app and then get your friends on it or, you know, figure out how to, you know, manage your PGP key or whatever it is, right? You always had some other cost, some other friction. You had to get a. What's that? What was the. The old browser extension, the beaver thing that, like, you know, wiped your foot, like, messed up your fingerprint, you know, like, yeah, yeah, yeah, privacy. Badger, badger. But like, you know, there's always like some other tool, right? I can't. I can't tell you how many times I had to download a little thing or do a little thing or get a different browser or A different chat. And because of that, like 99.9 of people don't have it.
A
And they're not.
B
They're not private, you know, like, it's just like if you have to do extra steps, if it's not built in, then it's just not. People are not going to care about. They're going to go for convenience.
A
People that want it like you were talking about anonymity set like you have no way to get it because you're just like, it's. It's clear by yourself.
B
If you're only one that doing it, it's like, oh, that's that guy who likes privacy, right? Um, yeah. And it is pretty powerful. I think that despite the fact that I've never. I don't think I've personally interacted or done anything with it other than turn it on in BTC pay, that I am pretty sure I. I want to go back now because I'm. I still have all that history, but I've like since switched my setup. But I'm pretty certain that I. I did a transaction with somebody and it did a page on. And I can't remember what it was that triggered me going, oh, wait, was that. Is that what that was? But that's potent that if. If that is exactly what happened, that it just happened without me interacting, you know, without me doing anything. Because I. I make a point to send everything through wasabi these days when I'm. Because I'm. I'm on a bitcoin standards, right. And I pay employees and people I work with constantly and get paid constantly. And I don't want to, you know, I don't want to have connections all over the place to, you know, my fold account or my river or my. My business wallet for my personal wallet, my vault. You know, like separating those things is like critical. And I know I don't have like perfect privacy. You know, somebody could probably do an enormous amount of work. But just having naive. You can't just like look at it and see everything. It's like super critical for just basic safety reasons. You know, it's not even like freedom and censorship. Resistance. Like, no, just like, you know, don't let everybody know everything that's going on because not everybody's a good person. You know, especially all the stuff going on with France and have you kept up with or. Or seen all this? Like some.
A
You're talking about a physical attack because of the physical records getting leaked. Government bureaucracy. Yeah, yeah.
B
Literal mafias that like now run on kidnapping people, cutting off Fingers threatening to beat and rape wives and kids to get your Bitcoin. Like, like literal, just horrible, like the most insane $5 wrench attack. And it's been systematized, it's been institutionalized. There's, there's just systems of people like that work for this thing that does this. And you know, governments are lately in the business of not even helping. They want low hanging fruit. They want to, you know, they want to kick out the illegal immigrants that have just like just chilling in their house. They don't want to kick out the, the people with guns and the murderers because they might get killed. Right. Like they don't want to do things that are difficult. And it just leaves like such a huge set of misincentives and it's just, it's bad. And like privacy is so important. Like if you don't take charge of, if we don't take charge of it ourselves, like we're not gonna get it. Nobody's gonna give it to us, you know?
A
Absolutely not.
B
And so maybe expand on that and like give me a little bit about your background and then how you have been tackling. You said you've been working on it since 2018. You've been working on this sort of stuff.
A
Yeah. So I was fortunate enough in, in college to already be sort of interested in bitcoin and on I think Reddit looking at it and I saw this tumble bit paper. I don't know if you remember back in the day, it's like. And a Tumblr. I'm like who the hell wrote this? And Ethan Heilman wrote it.
B
And what year was this?
A
I think this was 2017. 2018. Yeah. So he, he's the author of. The co Author of the OP Cat TapScript bip amongst many other things as well as I guess the, the, the post quantum bip360. But he was my TA for probability and statistics and I was like, I was like wait, I know this guy's name. And so I went and I worked with him in the undergrad lab. I really wanted to contribute to open source. Didn't know what to do. Contributed to some like some config on the C version of Tumblebit which wasn't even being used. Nicholas Doria from BTCPay was already working on the C version at this point. This is even before BTCPay as far as I know like n Bitcoin had existed. So he was working on the C version and that's how I fell right into the world because even the Wasabi guys They all worked on Tumblebit. So I spent a winter living in my friend's apartment. I stayed on campus and worked in the lab on this privacy thing that was really cool and hung out with some smart people. And I just got really stuck on that problem since. So I had one other attempt before focusing on Pay Join, which was a chain case app, which was a fork of Wasabi. I'm like, okay, I want this on my phone. Because I'm like, I don't want to my laptop every time I make a transaction. Because at that time Lightning was not a big thing for payments. I think there's a big distinction between like Lightning payments and general Bitcoin settlement now. But that was not the case then. So I was like, oh, I want this on my phone. That's the blocker. And then worked on that for a while and realized, okay, an application is not the thing that's going to solve this problem. Fundamentally we have to go and look at what Satoshi wrote and see like what's the real problem. And there is a privacy section in the white paper I'm sure you're familiar with. And it says all the inputs of a transaction necessarily come from the same person. So if you got, you know, if you withdrew some bitcoin from an exchange or you got something, you did, you did some contract and you have a coin, when you spend that to the next person, all those coins show up as inputs to a transaction and the person you're paying can see, oh, like you have, you have all this money and maybe $5 wrench attack you or even trace it back further. And there was a bunch of work on Pay Join around that time that just started. And the same people, Nicholas Doria and Mr. Cooks put it into BTC pay server and it got a huge amount of energy behind it. There were some barriers and reasons it never took off as well as reasons that they focused. I think it seems like they focused on what was working, which was btcpay and Page one was not working. So they're like, okay, this is a secondary thing. And it left a edge for me to start turning it into something that all these wallets could use instead of just an application specific thing and then teaming up with a whole bunch of people. There's now, I think the repository has like 40 different contributors. So you know, turning it into something that's a greater effort. And now it's piloted in the Page one dev kit. So this version that got created is piloted in Bull Bitcoin Mobile and Cake Wallet.
B
Bull Bitcoin kills it with these sorts of things. They do such a good job at implementing Shout out to Francis.
A
Yeah, serious. Shout out to Francis. Francis has been a very motivating ally and this year we're gonna. You're gonna see a whole lot more integrations coming. Because now the dev kit itself is generalized enough and stable enough that we can cut a version one imminently and it'll fit with basically any wallet.
B
If you get Cake. There's no way. There's no way they won't.
A
Yeah, they have it already. They've got the pilot since. Okay, 2025. So now if you open that wallet and you try to do an on chain transaction, Seth is always right there with that.
B
I gotta, I gotta give it to him. And. And then Nunchuck. Get Hugo. Get Hugo and Nunchuck and then everything that I do will be pay join. Because I know a number of people who just like kind of religiously use Cake. It's one of the best cake. Cake does not get enough credit. And then Nunchuck. I freaking love Nunchuck.
A
Me too. Yeah, we need a slightly different bindings. Like there's some more engineering work to do there, but it's not far. The tricky part is that page one's interactive. Right. So it's.
B
Yep.
A
It requires communication back and forth and most of the time when you're using Nunchuck, you're using hardware. So you either need to have the hardware plugged in or you need a really clean user flow where maybe you have to even sign twice sometimes. If you're like receiving and signing. That's something that hasn't been tried yet. There's a lot of discussion that's happened, gone back and forth with like Bitcoin safe and Cove is in the middle of adopting this. So I think, hey Cove, you're going to see it happen very soon. But it hasn't been the design focus yet. Yet. And there are still some kinks to work out.
B
Gotcha. So you brought up a couple things. One is, you said there was an intermediary, there was kind of a middle thing between Tumblebit and then when you got into Pay Join and then you talked about there were some barriers and some things that got in the way of earlier Pay join. I am a big fan of postmortems. I love finding out why things didn't work. And so I'm curious first off, what it did Tumblebit just kind of evolve? Like is that like a precursor to, you know, wasabi or these like kind of separate projects with just the Same theme and ideas, you know, or samurai or whatever.
A
Tumble Bit was just too early for so many reasons.
B
It's just too early. Okay.
A
Like, tumblebit. So tumblebit. ARC is really similar to tumblebit. And ARC is winning now. Tumblebit is like, you have to.
B
ARC is similar to tumblebit. Really?
A
Very much so, yeah. Because you have an operator that, like, forwards money once you pay it. So, like, the. I don't. I don't know what it's called in arc, if it's the operator. But, like, your actual. Like, your ARC has to have as much funds as people who are using it. So Tumble Bit's kind of the same thing. And it also came out before at least the FinCEN guidance had dropped. 2017 guidance, I think. 2019, it was 2019. FinCEN put out guidance talking about a difference between anonymizing software and anonymizing services and how the software is legal. The services are money service businesses and need licenses to be legal. And so that was way up in the air. And this company that was implementing its Stratus at the time was just like, we don't actually want to run this in the wild. They were a master node shitcoin. So they wanted their masternode to be like, the ark service provider.
B
Fun fact. Stratus is the only crypto that I bought, like, a good chunk of because of Tumble Bit. Like, when I heard about it and I was like. It was like 2017. I was like, okay, maybe. Maybe this is something maybe. And I bought and it's like. And it, like, shot up and I was like, oh, I'm a genius. I didn't even take my principle out. Like an idiot. No, no. I got crypto burned. I got crypto burned hard. And it was on Stratus On. Yeah. And. But like, they implemented Tumble Bit and then. And then, you know, it just kind of, like, fizzled out. Like, I was interested in that and the idea that, like, you know, you could do Stratus was going to, like, partner with bitcoin. Like, that was their big thing, right? Is that, like, we're going to. They're not enemies a bit. We're not competing. Right. And. But yeah. And then. And then I just. I think I ended with, like, 20% of what I put in. And I. And I 10x. I mean, like, all the bad decisions. I mean, cannot believe that, like, I could put in this amount and then. And then turn it into the this. And I didn't even take this back out. Like, just. Just so stupid. Just so stupid. But any Anyway, it could still go
A
to the moon, man. You can still hold now. You never know. You never know.
B
Anyway, so, so, so they wouldn't implement it because it was a service.
A
Well, they implemented it. That was a crazy thing. They hired all these dudes and implemented it and they just never like, they never shipped it as their masternode software. I think they realized they could make a lot more money hiring footballers, like soccer players to say Stratus is good than the risk that was worth like putting the master note out.
B
Yeah.
A
So. And like there was no lightning liquidity problem that Arc later figured out they could implement. But like the principles were. The principles were sound and it could have even worked as a, a payment channel thing. It was like payment channels and the Tumblr had two different modes in the paper.
B
Yeah, I kind of remember a lot of discussion about it because I was like, I was like reading and digging everything at the time and it sounded like such a cool proposal and there was like so many neat next layer or next step things that you could do with it. And that's why I was like, man, this could be a huge foundation and like we could use it for general payments and it would be cheaper and faster. You know, like there was just all this supposed benefits, but then I lost my, my money in Stratus and then I was like, what the hell happened to it?
A
And so what happened, I think was Adam Fixer was really focused on like just, I need to solve this privacy issue. The Tumble Bit team is not it. They're not going to ship it. So he did the zero link paper which turned into Wasabi's implementation. And the coin joins were just a lot simpler. It's like have everyone show up. You do1 transaction. Tumblebit was multiple transactions. I'm just like arc, you got to peg in and peg out and you have the, the non cooperative case that ends up being like a bunch of different transactions. And that, that made it. So it was much less clear that you could even make it economical. And then of course with Coin Join, they made money like Wasabi was printing money. They could charge for their business, coordinating and you know, make it make a percentage and sustain the thing. So meanwhile, like I said, Pay Join was coming, but there wasn't any way like to kind of post mortem that side. So I had forked Wasabi and that's. That was the chain case thing. It had an iOS app, but it was interactive and everyone needs. And synchronous. Everyone needs to be online at the same time and join around and the operating system iOS is not reliable enough to do that when you have the phone in your pocket and it's a cell phone, like it's not going to be connected to the Internet all the time. It's going to run out of battery.
B
Yeah, yeah.
A
So I realized a bunch from that one. You need an asynchronous protocol, at least one that's like optimistic. Like it could, it could proceed. It won't just fail, it won't get in a limbo state. And then you can't just depend on one application. You gotta have a development kit. Like you're already using Nunchuck and Cake. Like you, you're Bitcoin's probably already there.
B
You're not going to switch to a different wallet, you know. Yeah, yeah.
A
It has to work with the wallet and it has to work with the flow you're familiar with. So you're used to scanning a QR code, maybe to a BTC pay merchant and just clicking send. As long as the fees are within your parameter, you're sending them right amount of money. So that needed to stay. And that's where I did some hackathons and just really realized, okay, this, this thing has more attention and no one's picking it up because there's no clear way fund it. Like there's no coordinator so there's no revenue to be gained. So I worked for a bunch of time without any job to make the SDK work. And then Asia Ref had funded some, some of that work and then OpenSats existed and we're the first ones to fund that work specifically. And since we've had multiple incredible sponsors to multiple different contributors across the space and that sort of. Yeah, the grant ecosystem made it possible to continue.
B
Sweet. That's crazy. No, I agree on the whole, like, and it's just another one of those things that, you know, most developers are so focused on function, you know, can I get it to do what it does and just forget to think about what the user's doing, you know, and like, or what they're forcing the user to do and whether or not. I think that's like 99% of the time. It's the reason things don't get used is because developers think about it from, from the code to execution and the user thinks about it from what they're doing to, to accomplishing it, you know, like, like they think about it from interaction back and developer thinks about it from code to function, which in some sense has to happen. But that disconnect still ends up being Like, a huge, huge barrier. And it's funny that you bring up about tumblebit and then Wasabi and kind of like, why one may have failed and then Wasabi succeeded is I have become like a simplicity maximalism or a maximalist is. I just want, like, especially with, like, vibe coding and stuff. Like, I've gotten, like, I'd be like, which is my. The best database? And like, all this stuff. And I've gone through, like, conversations and iterations on, like. Like, I've been building like, three or four different projects. One that I've hired a team to build, and then I'm doing like three of my own personal projects around it or that will be plugged into it, so to speak. And after. And then I've got like, a folder of like, 40 little apps that I've built myself, and I've just. Everything now I'm just like, just make a JSON file. Just, you know, just make a JSON file with this. It's like, nope, I don't want. If I have to prove this, just. Just hash it and sign it.
A
This is funny, though. There's a piece of lore here. I need to interrupt for this hilarious piece of lore. So Wasabi did use a JSON file as their database, and that caused so many problems because it turns out you actually need to have maybe more like, multiple threads, reading and writing. But that's just. I'm adding.
B
That's funny. That's funny.
A
No, like, it does bite you at some time. Like, you want to be as simple as possible, but you do also, like, there's value in the software engineers who are literally screaming from behind you, like, don't do it that way. And you're like, but it's working fine. I've been doing this for weeks and weeks. It's like, software engineering is hard.
B
Interactivity is a very different game. And everything that I've learned with Pearcore and. And Pair Drive, the stuff that we've been building. Holy crap. You. You don't even think about how subtle and confusing some of the conflicts are, you know, about, like, who's got what, state of the index and. Okay, and if it changes in two different places, how do you. How do you reconcile? I mean, just like, there's so many little edge cases and nuances to it that obviously you can't just have like a basic. Oh, everybody's got JSON. But on my own computer, I have switched everything to just like a JSON sidecar file or a markdown file, like, across the board. You know, it's like, okay, if I'm doing analysis on this thing and I'm getting pulling camera motion out of this entire film, it's just a motion JSON. It's just a. It's just a sidecar file so that I can import it into all of my other tools or whatnot. But. But yes, interactivity. And especially when you have to prove or come to consensus in like a group, dude, the, the complexity of that is. Is kind of wild. And it's only because, you know, 10,000 other people have solved 10,000 of those problems, 10,000, you know, 50,000 different ways over the past, you know, 40 years, that that we actually have solutions to all of those things. Um, but, you know, Sloan steady wins the race. Actually, you know what? There's probably a lot of the audience doesn't know what the hell Pay Join is.
A
Yeah.
B
What is Explain Page Join. Explain what this is and how this is different from something like Wasabi.
A
Perfect segue talking about interactivity. Because that's what Pay Join is. Pageoin is the most basic way to make a bitcoin transaction where you introduce interactivity. And all this means is that the sender and the receiver both talk to each other when they're making the transaction. They both send messages to cooperate and have a transaction that has both of their input in it. So in this sort of batching history, rather than the privacy history, batching came up around stratus time when the. The chain traffic got massive. There was way more people that wanted to transact on the base layer than the blocks had throughput for. So all the exchanges started batching withdrawals where rather than make a transaction for every single settlement, they group them so that Alice, Bob and Carol all get their withdrawal from the same transaction of the exchange with one input. And that also this can get abstract real fast. But basically the exchange just doesn't need to keep so many different coins. There's. They can do some more management, but if they, if they batch together these transactions, that's how you get higher throughput in any, like any database. So that's. That's what's happening. Non interactive batching. Page one is interactive batching, where instead of just the exchange, in this example, doing the batch sending to the receivers, like, I guess a simpler example is you and I are transacting and you want to do a consolidation and I want to send you coins. And so rather than just broadcast a transaction that sends you some coins, I give you my proposal and I say, hey, do you want to pay join? And if you don't you just broadcast it and you get your money anyway. But if you do, then you can do the consolidation where you put your coin as input and merge that with the incoming coin so that you only have one coin in the end rather than two. So you've now merged the incoming money, incoming Bitcoin with your existing one. We've combined a settlement like a, like a transfer and a consolidation. The exchange example is kind of related to this idea of cut through which is it maps more cleanly on the batching. So Greg Maxwell 2013 came up this, with this idea of cut through where like oh, if, if these people premeditate their transactions, if I pay you guy and you know, you have to pay for your Internet bill at the end of the month, you don't have to communicate that to me. But it would be great if when I sent you money, instead of giving me your just your address, you were able to give me the biller's address and then I sent money to them and the accounting all squared up and Greg had a hole in this Bitcoin talk post where he's like, ah, we don't know how to do the accounting. Well, a pay join is basically the thing that does that accounting. It's this protocol that goes back and forth where I can pay you and then you can respond with a transaction that pays your biller. And I'm none the wiser. I get the pay join from you with your signature on it for your, your coin, whatever you want to forward to them and the transaction still sends the same amount of money to you. So I sign that and broadcast.
B
So it's nearly like a child pays for parent out of band. Right. Like almost in a sense it's like I'm just adding to the, the transaction to, to forward it into a different, to a different place. But we're putting it together into one transaction rather than splitting it, doing each piece individually.
A
Right. By communicating out of band, we don't have to use the actual blockchain to communicate so we can spend.
B
Yeah.
A
Like we don't have to spam it as much. Like if you're, if I'm sending you some coins that you know you're immediately going to spend, we're actually spamming like so you get. And, and there's some privacy benefit because these transactions can look indistinguishable from other transactions making people none the wiser that multiple people are communicating. So this, this assumption that Satoshi noted in the white paper, the most basic one, is no longer sound. Now there's a bunch of caveats as to why, you know, Bitcoin privacy is much harder than this. But yeah, basically you let instead of that assumption that Satoshi left in the white paper that one person contributes all the inputs, Pay Join is the simplest protocol that lets multiple people contribute inputs.
B
The reason I think this is the, the correct path is because it's like one step. And it's also one step that is not like, it doesn't increase, it doesn't create some like new primitive at the base layer or, you know, change our security assumptions or anything. It's just like, it's just like, okay, rather than trying to find the everything all in one privacy solution that solves every single thing, it's like, well, no, let's just, let's just break this one heuristic like, just like a little bit and see if we can get everybody to do it. And then like after you have that, then it's like, okay, well what's the next one we want to break? You know, like, you can, you can just start to like, piece by piece, block by block, expand this out into a true privacy like, interactivity. And on that note, this is my big question. How the hell do you do the interactivity? How do you connect? How do you encrypt and communicate? Like, this has like been my thing with Paracore and paradrive and the stuff that we've been working on. Is it like, okay, how do you establish connection? Whose server do you trust? Are you. Does everybody have to have tail scale? Are you communicating over the lightning gossip? You know, like, how do you connect to this other person to exchange the information? And is it universal or is it just like all the wallets pick themselves and we just have like a schema for like, what's the, what's the story there and how do you even solve that problem?
A
Yeah, there's, there's a lot in your. It was hard for me not to interrupt. There's so many things I wanted to say.
B
Yeah, I'm sure. Yeah.
A
Communication wise, I think. Yeah. Pageoin as the thing that works makes sense in this frame of. If you look at Satoshi's privacy hint as like, oh, all the inputs come from one person as a limitation not of Bitcoin, but of the frame of Bitcoin being non interactive. Then you realize, okay, interactivity is the thing that maybe addresses the privacy problem based on, based on what he wrote. Like, what's the, what's the one piece, as you say piece by piece, that we can move in that direction. I Didn't always take this approach. But yeah, I think this approach, the research I think is far enough now that we have a bunch of pieces we can implement and we have to kind of see based on where the wallets and services have appetite, have demand, which pieces are we ready to deploy. And we have so much demand already and the pieces are not ready. So like let's, let's focus on that. In terms of communication, we kept it as simple as possible in the principle of least information too. So the whole protocol is designed to use cryptography that's already in Bitcoin core. We don't want to introduce any dependencies to encrypt the payloads. And the BTCPAY version, I guess this kind of gets back to the postmortem there too. It didn't require any encryption, any universal encryption. So it was like you need encryption, but it kind of left it up to people to do it. So there were some implementations that use Tor, some that use tls, like HTTPs, the lock in your browser. But the BTCPAY implementation took off because it used plain HTTPs, because they were already running an HTTPs server, a web server, like regular web server encryption.
B
It's just sitting there.
A
So you send a request to the server that contains this fallback and then the server's response contains the pay join. The server can negotiate and send you back the pay join. The issue with this was that you need a server and there is mailing list posts back and forth. One that I think is that was referenced in the async page on the next versions BIP from Craig Raw where he's like, hey, like people aren't going to run servers. This is the problem. How do we fix this problem? And that breadcrumb led to the async page join protocol where instead of running a server, anyone can run a pay join mailroom and offer it as a sort of public good. You don't get any money for running one of these. It's basically a mailbox or like noster relay. Yeah, it's the same as a no relay basically. But it's a little dumber than a nose to relay because it also is just HTTP, oblivious HTTP, which means there's a mandatory proxy. So you don't leak your IP without needing to use Tor. Because although a lot of wallets use Tor, that's not something that really can be universal. If you go and look at wallets and services in the world, many just decide trade off is not for me. But oblivious HTTP is just like a little bit of sprinkle of cryptography on top of the typical web stack. And that's how Async page one works. So instead of sender sending to the receiver server, the sender and receiver both look at this mailbox. Just like email and the directory server, the mailbox can't tell the different pieces of mail apart because they're all encrypted and they're the same size and it doesn't get the IP address either. And so by depending on this, this dumb mailbox, Cake Wallet and Bull Bitcoin can negotiate a page one together.
B
That's awesome. That's awesome. So how's the mailbox set up? Is this just like run by. Is like Bull Bitcoin just running one and then Cake is running one just for the sake of its own users?
A
Bull Bitcoin and Cake have run them. They're not using them publicly right now because if Bull Bitcoin uses their own directory with their users, who they're also syncing with without Tor, for example, now they're collecting all the IPs and they can correlate stuff. So right now there's a small list of publicly run service, kind of like the default Electrum list. If you open Sparrow, it's community servers and the Pay Join foundation stores this list and communicates with the people interacting. And so like Vintium runs one for example, but anyone can run one. You can run one on a $5 VPS. Like it's dead simple. Like you mentioned a Noster relay. It's specific to the application, but anyone can use it and it just stores and forwards requests for a limited time before it drops them.
B
Nice. Okay, so how do you deal and, or think about like, could somebody just plug into this and just flood it to, to crowd it out? Or do they kind of have to have like mailbox addresses? Like, like I have to, I have to know that it's Bull Bitcoins. I have to connect to theirs specifically to flood. How do you deal with, like, how do you deal with spammers? How do you deal with malicious, potentially malicious actors plugging into this?
A
Blake Noster Denial of Service is not part of the protocol. It's like touched at, at the spec level, but it's, it's left to the operators for the time being. Just practically in terms of how do we communicate? If you open your Bull Bitcoin wallet and click Receive, what's going to happen is Bull Bitcoins has some cache of mailboxes that it's used in the past and it's going to Generate an address in the bitcoin uri, so like bitcoin colon. And then it shows your address and it shows some other information. That other information is going to have the URL of a directory server as well as a public key and some other information. And when you give that to me to send you money, I then encrypt the transaction, the fallback. And I know what mailbox that you're listening to and what key you're, you're using, so I can put it in there. And then you just listen to that one server and we communicate over that. And then if that server is not online when you're making the request, you can just choose to use another server. So it is like peer to peer in that it's not like a whole decentralized protocol. You're just using one server, but it's simple that way.
B
Nice. Again, simple. Simple usually usually wins. It's amazing how many like over the years like, like, like there's this like cool, it's seemingly cool proposal called Spider Chain and maybe somebody's even still working on it. And I've read so many proposals for so many different things and like complex systems and stuff. And as much as I love like thinking about some of these constructions, there are many, many times where I especially the, the more time goes on that I think it's like, this is just too complicated. There's going to be too many things that go wrong or too, too many, too many things that like, like kind of an attack surface or vulnerabilities that like we wouldn't even know until so far into this because of how complicated it is, you know, because of how many pieces are trying to move and interact and, and I love when it's just like, no, just how do you, how do you get it from, you know, A to B, like how do you, how do you do this easily? How do you just let people know that this is what they need to look for? This is, you know, like, like just, just go to, you know, bricks are simple and you can build a lot of stuff out of bricks.
A
Yeah, and that's another thing that helps with keeping the server super dumb is you do all the complexity on the client and you can put that in a universal toolkit and then all the wallets can just do it and they can share that infrastructure. And if it's simple enough, the infrastructure doesn't even need to be that expensive. We're talking about storing like an email's worth of data. This is not expensive.
B
Yeah, yeah, tell me a Little bit about devkit and how, like, for example, I'll give you a scenario. We're planning on plugging in Bitcoin and, and Stablecoin, actually Bitcoin and Tether into our software and I would love to, to, to make like lightning and like a bunch of things like available by default. We're using Statechain, so we're using the Breeze SDK or that. That's the intent right now.
A
Okay.
B
But I do obviously will, you know, have on chain stuff and I would love to have privacy. We're not really trying to make a wallet, so we'll probably just simplify this as much as possible because that's not really the point of it. It's just to have that interactivity because I think it's a layer that like you can really expand what you do when you realize you have payments and zaps in stump in something easily. But in the context of, let's say we did be like, okay, let's make a fully fledged wallet, you know, let's be very serious about this and let's add in privacy. I want to add in Pay Join. What does that look like for me? And how, how do I, what are all the pieces that I need to put in place to make Pay Join work for users? Especially when what we're doing has a peer to peer communication layer. Like the whole thing is about like making little peer to peer spaces so you have friends that you can say, it's like, oh, I want to make a transaction, you want to join me kind of thing. And like, so let's say we actually had that layer sorted out. How would I integrate with something like the dev Kit and utilize this?
A
I'm going to answer two different questions here because I think, okay, I think honestly the answer is not pick up page one Dev Kit and implement it. The answer is if you're using Breeze SDK to say, hey Breeze, you should,
B
you should, you should use it, do it for me.
A
And then everyone can do it. Because Pay Join is all about that on chain settlement layer. And we're seeing, as I alluded to earlier, like 2018, all the activity had to be on chain. But today we've got lightning all over the place and a bunch of different options for using lightning at varying degrees of sovereignty. Where Pay Join really sits is between all of those sovereign layers. So if you're entering an exit, exiting an arc or a cashew or a Fediman, like that's where. Or a lightning node, that's where Pay Join makes a lot of sense. And it seems like the best way to preserve user privacy. And what sounds more like a consumer app from a payment side, like, I don't think you're trying to create, I don't think you're trying to innovate in the way people settle. You just want like settlement in, in your app. So that is probably why you go off the shelf and you say, okay, Breeze is trying to figure out how we actually improve the settlement and we take it from them. Now if, if you were just an on chain wallet and you wanted to use the Page 1 dev kit off the shelf or just do a demo, you could get it working in an afternoon. Now I think it's around 2000 lines of code to just get like a page example working. I don't know that that means all of the errors are going to be handled gracefully and you're going to have all the persistence. This was as a, as of like last fall, I actually did an implementation and counted all the lines. I think that's still around. True. I don't think it's 10,000 lines. And we've really been focused on documenting it and making our reference. That is somewhat instructive for someone vibe coding so that you know what decisions you actually have to make and what decisions can be made for you, especially to keep things safe. So yeah, the off the shelf dev kit is in a bunch of languages now too. So we've got examples in Dart, Python, C Sharp, it's. The dev kit is in Cell, itself is in Rust and we have a system of creating these bindings. So like if you like Cove or I guess Bull, Bitcoin for example is in Dart and so they're using the Dart bindings. So if you have some new language you want to service, rather than rewrite all this code, check for correctness, do testing, you just pull the dev kit off the shelf and plug it into your language.
B
Nice. Nice. Okay.
A
I really think there's a difference between payments and settlement. My mind has changed and it's frustrating that like we are using the name page in some ways.
B
I want to know, like your day
A
to day payment has a completely different mechanism than Fedwire settlements, like any sort of settlements between banks. And I think that's the same for Bitcoin. Like there's just different sovereignty requirements, different threat model with a lightning payment of your coffee, which is what people obsessed about forever. They're like, bitcoin can't be used for a coffee, so it's stupid. And now Bitcoin is still stupid. Right. But versus like you're buying a house or really, I think collateral for loans is the more important frame for settlement because that's just how actual capital gets moved. So Pay Join is focused on that base layer because if there's not privacy on the base layer, there aren't privacy other places. And I think that's where privacy is lacking the most. I think that's where it's hardest because it's the, is just the most limited medium. You're actually going onto this public ledger and creating a record forever. So having that interaction show up to do the settlements as simple as possible has been our approach. And that's why I mentioned now, okay, it's not just Dan sending money to Guy. It's like these, these entities. You have your lightning nodes, your arcs, like whatever sort of an exchange that are doing the settlement from time to time. That's where the actual volume is happening on the bitcoin network. And those settlements are what are getting optimized. And if they can save some money, they have a big incentive to do it. Yeah, so that's our approach versus the payments we kind of have solved with lightning. Now I think the square terminals turning on was a huge moment where it's in the background now. You click the toggle when you walk up to the square terminal. You take out your, your phone and you scan it. And they don't even take on chain Bitcoin. It's just a lightning QR code because that is how the instant experience is served. You can't be waiting for a confirmation when you're in a cafe. So the, the use cases and experiences have specialized and will continue to. And I think we need to like the original pay join experience where the merchant is running the server. Just, it made sense to, for Bitcoin in those days where it was nascent and if you just wanted to kind of do a demo, you were going to do on chain Bitcoin, but like grown bitcoin settles into layers and we need to know what layer needs, what kind of solution.
B
Yeah, yeah, no, there's, there's so much in kind of what you just said. So I, I fully agree on the whole settlement and payment thing. And I've talked about and said as much on the show probably a dozen different ways over, over the years because I think it's a failure to recognize just how many like how deep capital markets are and, and like what the various layers and purposes of all the different types of transactions and exchanges there really are. And it's crazy to me. I'm Curious actually what you think about this because you mentioned lightning. I think about it, it's like yeah, lightning's basically solved most of that problem. Especially when you start talking about arc service providers and LSPs and state chains and all of these things merged together, right? These things being able to talk because of the, the, you can think about like the entertainments web of lightning that connects them all together, makes them all standardized essentially. And it's wild to me the number of people who still don't get that there must be a hierarchy of, of, of how to exchange. There, there must be different types of exchange and different degrees of sovereignty and different degrees of security. Not just because, oh, you need layers and you're going to have various trade offs for layers. Not even like purely technicality, but purely operationally. Like from the user perspective and from the business perspective. You need different, different things to be prioritized and different things to actually be softened. Like to loosen a little bit. And I'm curious what you think about. You know, some people say it's like oh, lightning has, you know, some, a lot of transactions don't go through which I don't even understand. Like I don't have any problem and I guess I mostly just use lsps or I have like a, a wallet that I guess it's, I guess it's mostly LSP wallets and I had just one. They're two big fat channels with my, my main node that I'm in the middle of swapping over. But how do you, how do you think about lightning in comparison and things I think people are just like, we don't have full, like, I don't even know how to say it, like fully sovereign, fully decentralized, everything's non interactive, payments for everything. That could be everywhere at 8 billion people. And so we failed. And all I can think is that like, like we literally have a system where you can, you can have a fully functional bank that, that is entirely permissionless, you can use it no matter where it is in the world and it's fully non custodial. And it's like how do you miss, how do you miss the quantum leap that, that is from fiat, like from what we're dealing with now. And you're like worried about like sure there's still things to build, but when is there, please tell me where the finish line is for this? You know, like, like that's, that's a 50x improvement. A non custodial anywhere in the world. No local jurisdiction, potentially even private bank that with no KYC with no nothing. Like, I mean, like, that you could just pick. That you could just pick a service provider from anywhere on earth and it could literally be a friend. It could literally just be some dude. Like, I, I think it was like Cali ran Lightning Tip or, or whatever that one that was in Telegram. We used it for like nine or ten months. He was running it on two Raspberry PIs in his home and had like 50,000 user, 100,000 users or something. He was essentially a non. Like, it just, ah, it's just wild to me. It's like, how do you not. How do you not see it? But anyway, without answering my own freaking question, I want to know what you think about that because you specifically brought up this idea that there should be this separation. And how do you think about it from the context of, like, criticisms on where Bitcoin currently is in its evolution?
A
It's evolved so fast that I think most people's opinions are just behind. Like, I don't even stay on the cutting edge of Lightning tech. Like, it's your money. You're not going to people. You know, people go to their local bank branch on the corner for 50 years and never consider different products. They just go there and they write their paper checks because that's what they've always done and it works and it doesn't cause them any problems. So I think when people use something new or if you use lightning like, you know, four years ago. Well, the anecdote that I like the most was right when Lightning Labs released their iOS app, like, technically there was a LND node on the phone and you could fund it and you could make an outbound channel, but there was no way to make an inbound channel. And there was just like, there was, there was no way to receive a lighting payment. It was very confusing. And I remember MIT Bitcoin club event. Like no one could make a lightning payment happen. That group of people cannot do it. Like, it's. It can't happen. And that's why that app didn't work. And that's why, like, we have LSPs now. And now, oh my God, we've got Async payments happening with LDK is very exciting because this stuff just moves so fast. So I think when there was even like three years ago, there probably was 98 success rate on lightning, which is insane. That's like broken. That's for a payment method that's broken. I remember going places and watching transactions get tried two or three times. Like at the Bitcoin Expo. And that's. We're at the Bitcoin Expo and the payments don't work. This is really weird. But that's totally changed, I think, especially if people are paying a, you know, a professional vendor. Like if you go to a square terminal and have your payment fail from a wallet that you've heard of before, I would be very surprised. It just doesn't happen anymore. I don't know if I lost.
B
It's funny in the context of like the payment doesn't happen or it fails or whatever is I. Which wallet was this? Is it Phoenix that did it? I can't even remember what the experience was, but I remember thinking, oh sh. Oh, that's crazy because it's like there's no reason for it to. For a lightning payment to fail because like if, if you can't get through on lightning, you can still just do an on chain. You know what I mean? Like, like, it's just. It's not like you don't have an option. It just means that liquidity has to shift somewhere. And I believe I was receiving a payment, I think it was Phoenix, and I did not have enough liquidity. And it basically just told me we're moving. Like we're splicing in additional balance and you now just have to wait for a little bit. But here's. Here's the money. Like it just like showed pending or something. And, and I was like, see, like this is like the perfect example of why it's not a matter. It's purely a technical problem. It's. It's like, okay, if there's not enough liquidity, liquidity, we simply adjust. Like we. You simply need an automatic system for exchanging the payment code into a on chain and then, and then finish the payment on lightning when it arrives. You know what I mean? Like it just. Or open the channel with the New Balance already to the user people who was like complain about like failed payments. Like, no, you're just. You literally just have to keep finishing. Like we had. We didn't even have spliced like splice channels. You know, you had to do like three transactions to get to actually make adjustments. You didn't have the, you know, the interactivity problem. Like there's just so many little things again, building block to you. Like one little block, one little problem, one piece at a time. But it's like, it's obvious we're going to get there. Like the leap that we have. You give the example of the first lnt like wallet or whatever. Like the leaps that we have gone. I use this all the freaking time and I don't think about it. And like how could we not solve the rest of the problems? Whatever, you know those, those still are at this point. I don't know. Yeah, it just, it just is. There's too many people working on it. There's two and it, and it works too good already.
A
There's a lot of people that want to get in the way. Like that's the scariest part is people are like no, I don't want this to happen. Like that's, that's where things could, you know, that's where the defense really needs to be mounted.
B
Yeah. I will say Steve, Steve from the simple Steve or what? Or Steve uses words. I can't remember what his tag is. He changed it. But Steve, Steve will give me because like I have, I've had like great lightning experiences and he has a, he owns a bar and, and has accepted lightning. He like worked really hard to get, get it all work and get everybody trained on it and then he's had like nothing, nothing but trouble and like a bunch of people trying to pay him has just like not worked at all. And I know he's like super frustrated and just completely sick of it. So he'll, he'll give me shit for.
A
I think some of that self hosting world is changing a lot too with everyone getting fed up with remote inference and the local inference being so much more available. Everyone like you see consumer hardware demand going absolutely through the roof. Like multiples in terms of crazy.
B
Through the roof.
A
Yeah, costs. So there's demand for people to run their own stuff. And I think when the lightning nodes first got on the scene like pre 2020say or right around then, that's when cloud was kind of at its peak. And so everyone's like, I don't want to actually use a computer. Everything's going to be on my phone and it's going to be remote. And I think that made it even harder to run a node. But from what I hear like way fewer people are interested in running a node because they saw people try to do liquidity management on their own and it was a huge pain in the ass and the software didn't work and oh my God, there's not even a way to back up like you have this channel state thing that's not the same thing as my seed words and that wasn't figured out. But I think, I don't know. Over the past year I've seen it be way quieter in terms of who's running nodes, but everyone that runs a node is like, oh, this got a lot easier actually. You can do it now. And I think we're going to see a resurgence in some node running in line with people running their own AI inference at home.
B
I kind of agree. I had a long conversation with somebody that like AI is literally making the desktop computer cool again. It's bringing it back and we're in a place and this is part of kind of like my, my thesis, my, my, my thinking about where, why I think this idea of like you can actually bring back peer to peer in a different way. And there's a way to make it work, not make it feel like a clunky peer to peer experience. And a lot of that is leveraging people who like we just have so many devices now and I think self hosting is just going to be something that people more and more think about it, think about specifically or directly more and more is like what's happening to my data? Especially businesses. Especially businesses. You know there's so many like, I think it's especially large business like corporations or whatever realizing they're using Quad and all of this stuff are, realizing what's happening is you know, Mythos or Fable five, whatever comes out and they're plugging proprietary systems into this. They're plugging like, like, you know, some company has like literally a database system that they have invented themselves a system for, for organizing, for collecting it just gargantuan amounts of data and, and fine tuning it to, to like filtering and, and curating exactly this. And this is literally their business is the curation is, is how clean and specific and organized their data. Is that in a, in a way that nobody else does or, or data that they have access to that they literally sell. Like that's their business. Right? And so many of these things are just running behind the scenes that just aren't public. It's just like how they do things or it's their software, it's their back end or it's their curated information and these things are getting plugged into Claude and, or anthropic servers and then Mythos comes out and suddenly it knows how to do all of these things. Like, like suddenly it's, it's able to answer questions like it looking at that proprietary data. It's able to code a come up with an idea for a database that just so happens to look a lot like Oracle's proprietary backend. You know, like, like, just like there's so many different things that's popping up Is because, like, they're using those conversations that you're having in the context to then turn around and improve their models. And then they're literally taking their proprietary data, putting it into an intelligence structure and then selling it back to them for token.
A
And people are catching on.
B
Yeah, people are catching on that that's what's happening is that they're taking all of their look, they're getting a window into the proprietary data and the proprietary systems of the entire Internet and then turning right around and retraining their models and then selling it back to people as a token. And I think that is going to heavily shift how people think about privacy because, like businesses, businesses will die because they shared information with a model to try to get, you know, 5% speed up. That ends up costing massive token costs. Yeah.
A
It's hard to say how it'll pan out because, like, is this just the inevitability of the singularity? Like, does it really matter, this just humorous intervention that we're doing? I don't know.
B
Yeah, I don't know. I understand. And I can think about it that way. I can see that perspective. But then I also see it that like, you know, what makes us, what makes us human is tied to our privacy, is tied to our individuality. Right. You know, you're a very different person when you know you're being filmed versus when you're, you know, in your kitchen. He's like, I'm making a pop and I'm doing, I'm putting my stuff in it. You know, like you, you act like you're you, you know, sounds like you
A
got a camera in my house.
B
Yeah. And I think the incentives and kind of the structure of society is, is even lost. Like it's fundamentally different if everybody is actually being watched all the time. Because, like, no matter how honest or extroverted someone is, there's almost always a, there's a public mask versus a private you. You know, um, and if you're forced to have a public mask all the time, I think there's this level of anxiety and friction in the world that genuinely changes the outcome of, of its, of its growth or progression. I would like to see. I mean, Page only being a perfect example is, is, I think not, not to say that like, oh, well, data and systems and ideas should be proprietary. I just mean it in the sense that like, what we want to keep private or we want to keep for
A
ourselves,
B
we should be building systems to allow that. And even as an open source maximalist, I think it's just Better to share ideas because you just want everybody to. But I, I'm not putting a gun to everybody's head to say, give me your ideas. You know, I think cooperation is just the, the better game theory. But, you know, just like sharing and cooperation are better. Socialism doesn't work, you know, and it's not because it's. Because that's not. It's the opposite. You can't, you can't force cooperation that you've, you know, it's an oxymoron.
A
Yeah. Privacy can be that exit element as well as it lets voice happen somewhat too. Like, you don't need. Not everyone needs to push and a pull their opinion. But you gotta be able to, like, it's essential to have that, like, uncensorable congregation and communication. Yeah, of course. I, I spend all my time on this like. Yeah, yeah, I totally agree.
B
Unpack what you were saying there with, with AI and kind of where you think those things are going, kind of. What do you see about the big picture? Are you really hopeful for privacy and where things are going, do you think? I think it's very easy to be dismayed and kind of depressed about kind of what's happening, but I think there's also a thread of, like, more people are aware of it because of how bad it's, you know, frog in the boiling water kind of thing. You know, the slower it is and the harder it is to see, the worse it's actually going to be. But if a gum's very apparent all at once, that likely just means something may be done about it. So what's your perspective on that? What do you see in the kind of big picture of stuff?
A
I tend to be optimistic to a fault, so I don't have the most, like, confidence in my predictions about this. I'm not making huge bets on what I'm about to say, I don't think. But like, other than I think bitcoin privacy demand is going to increase as people see it's possible and people have their, you know, economic life increasingly locked down. We're seeing it more and more. We're seeing even people like the solutions people use in the past for Bitcoin stop being options. And we're figuring out what the staying options might be, what qualities they need to have. The AI stuff's optimistic for me. I feel like if you're someone that, like, it depends on who you are as well as what kind of resources you have, whether you're enabled to wrangle it, because if you really don't have Like, I don't know how, I don't know how kids engage with this stuff naturally or to what degree they can, because the, the AI stuff I use is not free. But it is promising that we're over the hump of, like, use as many tokens as possible. Spend $10,000 a month on tokens. It seems like around $100 a month, $200 a month. A, like less than $1,000 a month is how much, you know, you can, you can effectively use as an individual without your, like, just imparting your own judgment. And I don't know if that's, if there's some balance between like, the cost of intelligence coming down and our ability to use intelligence and go. Going up that keeps that at a level, but it seems like we overshot and it came back down. I'm rambling a bit.
B
No, no, I totally agree, I totally agree. We like, way, way overshot. You know, there's so many different, like, major corporations that like, went hard, went full in on the Uber's. A great example is they, they did, they had like an allocation for how much they were going to spend on, you know, Claude, and they, they literally gamified it to get, like, employees to use it more. And so many people are in this. Like, no, you need a prompting loop to have the AI and Lubin just needs to go on and on until it solves problems and all this stuff. And I'm like, I am not that. And there's a reason Uber, in like three months or four months burned through an entire year's worth of token allocation and now they're like, shutting the whole thing down and they're like, limiting everybody. And this is not, this is a common story now.
A
I've, I've, I feel like you had to air that way. It was important. You had to, you had to oversubscribe. You weren't, you weren't trying enough. Like, you didn't know where the, where the benefit was. And I feel like most of the choices in life come down to, like, which direction do you want to make errors in? And I feel like that was the right direction and now everybody, you have
B
to oversteer one way. Which way. Yeah, no, I, I completely agree. In fact, it's, I always think about, like, the economy and honestly, life decisions, just like human decisions in a giant complex system is driving blind and then feeling what has occurred after you steer. So like, you're, you don't know which way the road is turning and you're trying to predict it from all of the little things and the pieces and the people you interact with. You know, you're. You're feeling the wind and. And the. Which way your car is leaning just a little bit or whatnot. And you're just. You're just blindfolded the whole time. And so you turn one way and then you get. And you're like, oh, shit. And you're like. And you turn back. You know, like, that's the. That is the process of life and economic progress. You have to find the barrier and. And do it wrong too. A little bit too far to know which way you have to turn back. And, you know, price and economic systems work exactly the same way. You only know a price is overbought or oversold if there's an opportunity to profit from it. You know, like, it's only. It's only when it's too high that you then realize there's an opportunity to get it lower, like, et cetera, et cetera. Like, again, it's blind until you start the interaction with it. Maybe you don't want to talk about this, and that's totally fine, but I. I feel like I have to ask, just because it's Twitter and maybe it's just my feeds just full of it. What's your thought on, especially when we're talking about settlement and base layer stuff, what's your thought on spam? What is on the whole fork conversation? Do you even have an opinion on it, or are you just like, I just need to work on pageoin and just care about privacy? Or do you have, like, a philosophical or technical position on that at all?
A
Yeah, when mempool's empty, it's tough for me to, like, have that draw with so many other things on my plate. I'm definitely the guy at bit devs who, like, tries to. To squirrel away from this conversation because, like, there are just. There's so many, like, really pressing dangers and problems and, like, things going off the rails that I've. I've kind of stayed blissfully ignorant here. Like,
B
honestly, it's probably the best. Yeah, it's probably for the best arguments.
A
You can look at my Twitter. I don't know if you'll find, like, I probably.
B
I didn't see anything scanning, so I was just. That's why I was just curious.
A
Yeah, I think. Who do I need to shout out right now? The Bugle. You gotta. You gotta follow the guys. The Bugle. I think even if you don't agree with them, like, that is my engagement with the filter conversation, to be honest, with you is like, I bitcoin bugle pretty frequently. Just funny, like. Yeah, I don't know. I, I wish I had something more substantial. It's just not my piece.
B
No, totally it.
A
Yeah.
B
Again, this. Oh, excuse me. It's probably the safe way to do it. And I, I tend to agree. I, I've gotten wrapped up in it just because I, I respect and like people on both sides of this debate. And I feel like it's part of my obligation to try to learn and, and get, you know, conversations with both people on side, on either side, because they're just gonna, you know, this side's just gonna call the other side a pedo, and this side's gonna say you're just technically. And so, like, if you don't have conversations, you're never actually gonna make inroads to anything.
A
In terms of consensus changes, though, I think there are opportunities in the future. I just don't really think the, the filter one is the most likely to, like, manifest.
B
Yeah, I, I, I honestly don't think so either. And one of the points you brought up is that when the mempool's empty, like, it's hard to feel super. You know, if, if fees were $50 for every settlement and we still had 60% JPEGs in every single block, that would make me convinced that we should think this should be considered a little bit more serious, you know, is that, is that genuine monetary activity is being squeezed out by Dick Butts. But when the block is going to be like, 60% empty because, you know, most payments have been shifted over to lightning, it's a question of whether or not there's any, even any sustainability to it. You know, does it exist at all at $50 a settlement? Because I think that's where we go, you know, like, that's, that's where this ends up. Granted, Steve might also challenge me on that because we've basically been the same sats per bite for, for like, 12 years. And everybody's saying the fees are going to go high, the fees are going to go high, the fees are going to go high. And it hasn't. So I don't, I don't have much evidence other than just, like, intuition that will end up there. Um, but yeah, we gotta create the demand, right?
A
The thing gets more effective and then people want more of it, even though it's more expensive.
B
Yeah.
A
Um, yeah, you brought up cross input signature aggregation at the very beginning of this call, and I feel like that's, that's where I could see some energy A year from now, believe it or not, I know the proposals are making progress. Fabian Yar has been working on them
B
and
A
there's some fun play with pay join. So the two of us pitched Cipher Tank in Lugana last year. This idea of ISA like pay join, input signature aggregation. Because to make cross input signature aggregation work with the full aggregation, you need to do interactivity like the sender and receiver, everybody that participates needs to do that. I don't know that the current version of pageoin, like two party page join really works here. But if page one is your fundamental interactivity protocol and Caesar lets you, you know, compress that even further, these things play really nice together and you will see advancements there. You know, there's like two major things with pageoin that can improve. There's like, how much better can you batch? And then how do you plug all the privacy holes? And they're kind of the same thing because right now you have all these sideways leaks, you have all these other cluster problems. So like beyond the ones we're really familiar with, there's a lot of new work about, you know, if someone always does their transactions between noon and 2:00pm East Coast Time versus West Coast Time, you probably can distinguish their clusters. Even if there's some pay join between two people happening like beyond, beyond the, the multi party heuristic, the common input heuristic. So we need to have the protocol evolved so that multiple people can come together and batch, which means more complexity. I think it just needs to happen gradually. But where I think there's just a lot more push for something like that to happen, cross input signature aggregation than some of the other proposals we've seen recently. If, like, if you can get a, like a synergistic, you have some privacy, you have some batching, I think it's easier to get something across the line. Like the opcat stuff has not been easy to change. The post quantum has not been easy to change. The filter conversation, although like, you know, not necessarily a fork conversation explicitly is a dumpster fire. Like it's really not easy to. Nevermind easy to change. Like it's not even easy to talk about. And like Taproot came and people didn't really implement, kind of did. I mean now, now everyone takes it, but slowly.
B
Yeah, actually how does that, how does that interact? I'm curious about page one dev kit and everything. How does Taproot do y'. All, do you have taproot by default taproot implementation at all? Like, like how do you use that? Or are you not even worried about it, you're just kind of focused on like getting it to work with the normal setup.
A
Now in terms of dominant mechanism for page one, like it doesn't even. You really need to use the Bitcoin network, to be honest. As long as you can send a payload that is a transaction, the page on protocol doesn't care. So you could use it on, on any network. You can use Taproot or any, any sort of script, the first version.
B
So it's basically, it's not really tied to anything in particular. Like if your wallets both use Taproot, you can just use Taproot in the same way.
A
Yeah, there's fingerprint problems, big fingerprint problems. If your wallet is constantly using Taproot and my wallet's constantly using Segwit, we can pay join, we can break the common input heuristic, but like our fingerprints are still really help. So until you get a bunch of people like multi party pageoin, multiple receivers, multiple cut throughs, that's a big privacy problem. It only really helps the clusters that have similar fingerprints. But page one itself is the. You need to implement the transaction construction and then the library takes care of the network messages and the serialization and like persistence. But as long as you have some sort of transaction you want to send to your counterparty like a psbt, if you want to get jargony, then you can do the page on the Page on dev kit. And the protocol doesn't care about scripts. The way I like to think about it is the wallet should be concerned with the like policy, like what kind of transactions they want to participate in in terms of fee rate, in terms of script, in terms of amount. And then the pay join protocol is just the, just to coordinate the two to be able to have that conversation. The page join protocol, especially bip77 sort of refined the stuff in the v2 from the the v1, so the async version really. And in the effort to do that we even edited the the V1 so that the wallet can make the wallet decisions. And then Pay Join is really just about enabling the conversation.
B
Okay, I'm curious. It's a little bit reversion to something we talked about that I want to just get clarity on in the context of the interactivity is how does the signature work in the context of adding. So let's say we have three people. So we have three people. Since I brought them up like three times, Steve, myself and you and you are sending me a transaction, then like, like I give you an address, and you, like, make a transaction, but then you send me the actual transaction out of band so that I can, like add something to it. Do you then need another interaction and can I send it on to Steve? Because, like, I'm paying him in part of this, and then he can tack onto like, is this like a. It is an interactive thing that we can expand the transaction, but can it still just be tacked on again, like another time? Could this be passed around in like a group of five people? Or does it then have to go back to each person to sign each new piece? You know, like, I have to sign it with Dan and Guy, and then Steve has to sign it with Dan, Guy and Steve. You know, I mean, like, how does. How does the construction of the. The signatures and the kind of proof of the pieces of the transaction occur since, you know, hashes and stuff change every single time?
A
Yeah, the signing. This could be broken down into roughly what exists today and what's possible. So, okay, today we do have one round of interactivity, which means I send you a message, you send a message back to me.
B
Okay.
A
But it's possible to make a protocol that has multiple rounds of interactivity or communicates with multiple people. So to answer your first question about, like, how does this work with signatures, when I send you some money and you want to also cut through to Steve, if I understand the example, you'd give me your Pay Join uri, which contains the address and the mailbox information, and I would send you a fallback transaction that pays however much you asked for in that uri. It's got some amount to say. You then do what's called output substitution, where you alter the transaction. So you replace the output that pays you with an output to Steve, say, and you also have a chance to add your own input, and then that's it. You could also do change where you could. Like, you could replace your output to you with one to Steve and one to yourself. If you don't want to forward all the money I'm sending you to Steve. So yeah, that invalidates my transactions, of course. Because if. Well, it depends on. There's some nuances, but typically people use sig hash all you're signing the whole transaction and that you got to invalidate my transactions, but you'd still sign your input and you'd give it back to me then. And I. Not only do I have the signature on the transaction if you contribute your input, but we also have a signature out of band. Like all these Pay Join messages are signed. So I know it comes from you no matter what. I know it's associated with that key that you gave me in the URI when you gave me your address. So I have this message potentially with output substitution that is the Pay Join. Now it's your proposal of what's a page join. It's still spending my inputs, but maybe that address changed from Guys to Steve's. And because I still have this Pay Join protocol signature, I know it's from you. I'm comfortable signing the transaction and saying, okay, I know this message came from Guy. I'm not spending any more Bitcoin than I was before. And then I broadcast that to the network. And so you're watching it for the network. And when Steve opens his wallet, if the output was meant for him, he's going to say, oh, I got some money. And he, he probably thinks the input came from you. He doesn't even know. He probably gave you that address labeled it Guy. And it just shows up in his wallet as from Guy. But I actually sent it. And that's where the cut through the net settlement is like, I think boon for privacy, especially because you know, you only have the information you need. Steve only knows, oh, I got some money from Guy, but it doesn't mean the actual input is from Guy anymore.
B
And what's funny is that like I know I, I, I could totally change how I do. I would actually like to be able to. Wait a second. I think I actually can do that. I think I can batch in nunchuck and I just don't do it. I think there's like a dropdown that I can like add another thing.
A
I think so.
B
That's so stupid.
A
Send money forward.
B
I totally should be doing that anyway. I do individual transactions all the time. You know, you get used to doing the thing a certain way. So just to, just to clarify, because this seems like like respect for, for dealing with all this because this seems just like super, super complicated or just like nuanced in like the different pieces.
A
But I'm glad we're doing this at the end.
B
Yeah.
A
Later. Not at.
B
The first thing is when you send me the transaction, then I'm add my details to it and, and sign it. I cannot send it because any previous signature or whatever, since I've edited the details of the transaction is no longer valid and I have to send it back to you to do a final signing. And you would have to broadcast. I would not be able to broadcast by myself. Correct?
A
Right. If you broadcast that, it would fail consensus. It's Not a valid transaction.
B
Gotcha. Is there a way to you know the non interactivity holy grail with Caesar or something like that to basically add without having to send it back and get a new signature and still have like a valid. Like like I've. I've simply added my, my input and the signature for that piece of it to the. The witness data, you know, whatever it is and then broadcasted it. Is that, is that possible where I could broadcast it or I could send it back you. To. To you for you to broadcast. It doesn't matter. Anybody could broadcast it and basically we can just have additive things. Yeah.
A
On a transaction this is what's usually meant by like covenants. So there's.
B
Yeah.
A
I. You would need new script. I don't think without consensus changes to new script, this would really be possible. Okay. And yeah, there's like, there's a bunch of way to do ways people have thought of doing this but patron is kind of like the really dumb way. If we assume there's not covenants, just make it work. Like what can we do what rather than like. How do we get around interaction to do the specific application. The frame page join that I'm familiar with is working in is like given interaction as crappy as it is and as much of a pain in the. In the ass as it is. Like if we can give interaction, what are all the things that we can do with that? Yeah, yeah. Starting simple. So like the example you gave is we just have interaction and now we can already do all this cut through. Like I can deposit to an exchange and direct directly fund the people withdrawing. This is just with the basic two person pay join.
B
Now that's great for batching with an exchange because it's just better for them.
A
Oh yeah, yeah. That's. That's like also coming. Like stay tuned. You will see that soon.
B
Yeah. I'm actually curious on that note, who have you been talking to? Because like a big part of this would obviously be getting everybody on board to use this. You know, I would love to. To feel like, okay, now we have like some sort of a standard, some sort of a thing, the mechanism to use. Who's going to implement it? You know, do you know, have you all been talking to people specifically other. You know, you mentioned bull, bitcoin. Oh yeah. And cake. Who else? Like what else do you see as being like low hanging fruit for? Like if we could do this, we could get an enormous amount of support throughout the ecosystem and then it would make sense for these other five or ten Wallets to implement it simply because it's available in, you know, this, this, and this. You know, like, what's your. What's your kind of like, target or framing for, like, how to get people to jump on board.
A
I don't know if it's just one particular thing because it's an interactive protocol. Like, you need the counterparty to always have it. So it needs to be available for everyone to integrate. And the good thing is, I think people are on board for. And they have been for years. People have been pretty unanimous that they're like, okay, Pay Join is an upgrade. It's kind of an optimization. If our two wallets are online, they can communicate and we should try to communicate. And if they don't, you fall back and it's fine. The real bottleneck has been the engineering to supply the demand. There just hasn't been a page on Dev Kit before and everyone needed to do their own integration. And after doing the page on Dev Kit, like, focusing on this for a few years, like, it's complicated. Anytime you have interactivity and if you look at lightning as an example, like, it, bolt 11 was out everywhere forever, and now we have bolt 12, like, kind of making some progress. This stuff is just not easy. But we're past the point now where the bottleneck is engineering, which is a really like. That was one of the reasons I think it makes sense to do the podcast now, because someone can genuinely take the page on Dev Kit off the shelf and plug it in their wallet and use it. I think I can talk to Bull Bitcoin Exchange wanting to implement this because Francis has been, you know, there's tweets from him from like 2020, probably where he's like, oh, we need a white label page. One thing I need to be able to use this off the shelf. The implementation is way too hard. Like, it's just not, you know, it's not what I'm focused on. I. I think he would agree with this framing. I don't want to put words in his mouth, but, like, he's been very vocal and supportive of Pay Join and the fact that he wants it for the exchange. And it hasn't been possible. And I think once that is demonstrated as possible, especially with the mobile app, where you don't even need to show it as a Pay Join at all, it's just like you click Buy Bitcoin or sell Bitcoin and it totally happens in the background on the app. I think then others will come to see there's active development on a BTC pay server plugin by community contributors, so by Valera and TRVIC, who's sponsored by BTrust that you will see. And I think that's another one where you have a bunch of people using it in BTCPay and if they can upgrade to the new version and then Cake Wallet and Bull Bitcoin can use them. And like I said, Cove is active. There's, there's a bunch. There's like, I have a long list of like 40 integrations. And yeah, the. Stay tuned. If you, and if you have anyone in mind, I'm really curious who you think would be a good next target. You mentioned Hugo and Nunchuck. I think that's somewhere that we haven't been looking directly because it's just a different bindings thing, but kind of the next thing on our roadmap, after cutting this 1.0, which is like a this week thing, then the floodgates are open. Like the barrier to using this stuff is not that the protocol tech isn't ready or that the protocol implementation isn't ready. It's that like, oh, now I just need to wire it into my app. That's where we're at right now.
B
Yeah.
A
And I mean right now. Like, like last week that wasn't the case.
B
Yeah.
A
This week, now we're here. Like it's happening right now.
B
That's awesome. That's really awesome. Now I would love to see this be a standard because like I feel like, and you know, correct me if I'm wrong, this also is like a brilliant way to get around all the regulatory like problems or like targeting like, oh, you're providing a service. It's like you can't just, you can't tell me that I can't just like, like we're making a transaction together. Like you and I are making a transaction together. You can't tell me that I have to do it a certain way to not include you, that we can't share information separately and like add it to each other. It would be like, it's like you have to have a one to one message. You can't like out of bounds, just like put two messages together somewhere else and then, and then send it. You know, I like the, the ability to subjectively define that from like a legal stance just sounds like an absurd task to me. You just have to make all communication illegal to, to essentially try to justify that. And I'm curious how, how do you think about it in that, in that context? Is, is that sort of, is that kind of Part of your, your risk profile for why this is such a good way to do it because it's not a service provision, it's not a pool of privacy coins or whatever. You know, it's not, it doesn't run into the tumble bit service provider problem. You know, like it's just like are people allowed to communicate and like put a transaction together or are they not? And why wouldn't they be
A
both? The fact that it's just a cooperative interaction happening without a service provider or like with an arbitrary service provider, like an arbitrary server, like it literally a mailbox is very similar to lightning which is you know, getting lindy. And it's not overt like the coinjoin tech or like a mixer tech, if you call it tech really was before. It blends in and it's happening in the open and it's transparent to both sides. So both sides know what's happening. It's not like, it's not like I'm sending money into an abyss and trusting someone that the money gets to the other side. Like if we're participating in pay join, I know I'm getting exactly this much money. I have a record of exactly the money I put into it and what I got out of it. I think it's a lot more incentive compatible especially when you can save fees. It's a lot harder to just like not want to do it if you're leaving money on the table. Especially fees raise up, you know, demand. As demand grows for bitcoin in general, as bitcoin becomes more useful. So the whole shape has been designed with this in mind. Just like the, the focus has been on the thing that might have some longevity and staying power, which means making a lot of trade offs to be fair. Like if you're using a coinjoin, even though it's probably harder to have specific privacy guarantees about definitely seems to most people like they have better privacy than from their typical pay join. Right. If you're using a coin join and you have a new coin, it's not so clear exactly how much work it takes to figure out how to connect the input and output. Like maybe it's possible on some timescale with some analysis, maybe it's even trivial if you have good enough math. But it sure seems like it's a lot harder than just looking at the raw bitcoin ledger. With page one, it's, it's less clear, right? You're just like your counterparty still knows what you're doing. But these things, these things work together. They're solving slightly different problems. And pageoin is, especially with a page one dev kit is more of a platform to evolve the protocol. So once you have this interactivity like, okay, and I think people thought, and maybe some people still think lightning is, is this, but Lightning has a different complexity. Like Lightning, you're managing the state of all these different nodes. You have gossip. It is really a decentralized network. And if your goal is just like what can we do if we have minimal interaction on Bitcoin? Maybe you don't want to implement lightning node software every time you plug your hardware and like your hardware wallet, maybe your, your vault is not that. So it's, it's serves a slightly different niche that all plays together. And for the exchanges, like if they're still getting the same information from their customer, they know how much money they got, they still kyc them. I don't think that changes their compliance posture at all.
B
Yeah, yeah, that's a good point. And one of the things that I really like about this type of proposal and the one that comes to mind that kind of had a similar privacy profile or had a similar relationship to this one element is something like Dandelion, you know, the, the propagation delay protocol. You know, flip a little coin to. Yeah. For sending out a transaction on the network so that you can't time how you received the transaction at different points in the network with different nodes and then basically trace it back to where it came from. It's the original node that it came from. But one of the things that I thought was really, really interesting when I was digging into how it worked and how it affected privacy at scale was that like if 20% of the network or 30% of the network adopted Dandelion, basically the heuristic for telling what happens to the other 70% of the transactions is broken because you still just don't know if there was a dandelion somewhere in the mix. So like partial adoption breaks the reliability of pinpointing the rest, the people who aren't using it. And one of the interesting things about Pay Join, aside from the simple like one UTXO to two UTXOs, anything that's slightly batched or has multiple UTXOs, multiple inputs and multiple outputs, which, you know, a lot of, a lot of normal wallet, turns out tons of mine are multiple UTXOs to multiple UTXOs just because I don't have enough in one UTXO to send the transaction. And because of that, nobody has any clue whether or not that was a pageoin or not. Except me.
A
Right. And so just by having Pageoin too, you're doing.
B
If you had 20% of the DOC network. Yeah, yeah. If you had 20% adoption and there are 40% of the network is multiple UTXOs to multiple UTXOs, you have no way of knowing that only half of those are page only, or if all of them are page only, you fundamentally alter the heuristic for the entire network just by having partial adoption. And that's a, that's a really powerful element that it's privacy in the open, so to speak, and that you're actually helping the anonymity set, even. Even if everybody doesn't get on board. So the. That's always a. That's always a really cool element. I love the, the kind of nuance of these types of solutions to those problems. Yeah, we are already. Okay. We're at an hour and 55 and I've got. And I got construction guys probably going to show up here any minute. Any other, any other final thoughts or anything you want to add? This has been. I love this stuff and I'm happy to be able to. If any of the audience doesn't know about this or hasn't heard about it yet, like, it's super awesome. Everybody should check it out. Everybody should follow you. Everybody should follow everything that's going on with Pay Join. Is there anything else you want to add or something you want to share for everybody who's listening before we close this out?
A
Yeah, I gotta thank the donors to the contributors of. Hey, join Dev Kit. You know you've got Spiral, Open sats, Human Rights Foundation, Maelstrom.
B
Wow.
A
Vindium sponsoring some contributors, B Trust, mit, dci. Like, there's a lot of people that are unnamed to Cake Wallet who've generously supported and made this possible in a decentralized way. And it's growing. You can go to page1.org to check it out. I'm at BitGold B A T G O U L D on Twitter. Yeah. If you are in a position to do an experiment with a wallet or service, I would urge you to point your Fable 5 or whatever subscription you have at the dev kit released and try to get a demo working. I know. Like two weeks ago, three weeks ago, around the time of BTC Prague, There was a demo of an ark getting onboarded. Like a cashewman getting onboarded. The cashewman backed by an ark doing this cut through. So typically, because the ark transaction is complicated, it's not like your regular wallet knows how to board the ark. But if it, if your regular wallet supports pay join, it can send some funds to this complex wallet. The complex wallet can do a cut through that pegs into the ark, send it back to the page wallet and you can board the arc in one transaction. So I'm see. And this is all vibe coded like by Matt. Yeah, so this is, we're seeing like, like I said, the time has come for integration. If you're excited and want to experiment and if you've got, you know, more, more complex service or hardware exchange, I encourage you to reach out and experiment because I think you'll find some success.
B
That's awesome. That's awesome, dude. Well, shout out to you and everybody who's been working on this. You know, like I have endless respect for, especially the more I, I try to dig in to have projects of my own development, I have more and more respect for the people who actually stick to it and, and get things to the finish line and produce things that other people need and use and really, really value. Because if we don't have thousands of people doing every little piece of this, like it doesn't move forward. And it's wild how much like one person can actually make a difference and how little value or how maybe gratitude that we, that we just kind of like somebody will do it, you know, like we just kind of like hand wave it away sometimes. So shout out to you everybody with payjoin and everybody who's just putting in, everybody who's tried and failed and everybody who's donated to all of this. Like it's, it's just awesome to see it. I like you, I'm a endless optimist, you know, and it's awesome to keep having conversations like this and seeing things move piece by piece to the place that we want to end up. So thanks, man.
A
Yeah, and thanks to all the contributors. There's lots of people who, yeah, seriously work on this mission and people don't even know about it.
B
Yeah.
A
And a lot of the time it's for free. Even though there's a lot of donations, there's a lot of the time people contribute because they're just motivated. They just want to see it happen. So yeah, thanks to everyone that's contributed.
B
That's awesome, man. Well, dude, shoot me any links or anything to make sure I get it all in the show notes. So I'll grab my AI to list out everything that you said here at the end and, and I should have it all. But if you think of something, just shoot me a dm, let me know Cool.
A
Thanks, guy.
B
Yeah, dude, thanks for coming on. This is awesome. That'll wrap us up. Another shout out to Dan, another shout out to everybody who is all the dozens of people who have put. Hell, maybe a hundred more people who have made this happen, not only in this current iteration and the contributors, but in the past, the donors, the previous projects that, you know, came and went to make this all possible and get to an implementation that, that may get more steam and may go further than all previous ones. Having learned critical lessons, God, I would love to see this implemented far more broadly, especially with exchanges. In fact, I didn't even mention it to Dan, but I think he should go for Strike, River, Swan, Bull, Bitcoin, Coin, Floor. I think, like, you know, all of this, maybe Coinbase, I don't know, maybe Coinbase is a lost cause, but to get the service providers to do this. And I love the little setup he talked about with Ark and how cool you could do some of these little systems and, and consolidations. So check it out. If you're, if you're a builder, if you're building a wallet, if you're, if you work with a service like let's say you work for Swan or you work with Strike or something, make, make some noise, you know, push it up the ladder, talk to people. Let's see if we can get this implemented. Because I would love just like, like one notch, you know, like get to better privacy in a way that doesn't require everybody to download a special wallet or adopt some specific service or anything like that. Like, like this is, this is how we make real progress, in my opinion. And this is just really, really promising. So excited, super excited. I'll be sharing it out. I'll have links and details in the show, notes in the description, so you should be able to find it really easy. I'll have everything that I can get. I already got. Dan's going to send me any links that I missed and yeah, get yourself a bitbox too. This perfect, perfect way to hold your own keys and then also use it with a pay join implemented wallet. Beautiful, beautiful. Hold your own keys and privacy. It's just the way to go. And you get a discount and you help out the show and share it out with everybody. You know this, this show lives entirely on word of mouth and you sharing it with people that you know and who want to hear about cool things and learn more about Bitcoin. So that'll do us. Thank you guys for listening. Get a bitbox, support the show, subscribe, follow everybody and all the projects and I will catch you on the next episode. Until then, that's my two cents. Sham.
Episode Title: The Time Has Come for Privacy on Bitcoin with Dan Gould
Host: Guy Swann
Guest: Dan Gould
Date: July 10, 2026
This episode explores a pivotal moment for privacy in Bitcoin, focusing on the rise of PayJoin and efforts to make privacy a default, seamless feature for all Bitcoin users. Host Guy Swann dives deep with Dan Gould—a key developer behind PayJoin and its new Dev Kit—on why privacy matters, what's historically stood in its way, and how the latest developments could change Bitcoin's privacy paradigm forever. The discussion is practical, philosophical, and highly technical, delving into protocol details, user experience, and the broader implications for Bitcoin adoption and safety.
Snowden’s Impact & the Digital Panopticon
Dan explains his journey into privacy, crediting Edward Snowden’s revelations as the wake-up call that made him treat all digital interactions as “inherently recording devices.”
“When Snowden exposed all this surveillance... I started treating all digital infrastructure as inherently recording devices... when it comes to money that reveals all the relationships someone has, and without privacy, there's no way for that to be free.” – Dan (00:00, 06:21)
Privacy is essential for Bitcoin’s censorship-resistance and freedom.
From “Orange-Pilled” to “Privacy-Pilled”
Automatic, Frictionless Privacy
The Anonymity Set Problem
Violent Real-World Risks
From TumbleBit to Wasabi to PayJoin
Postmortem on Failures
Definition and Mechanism
PayJoin is “interactive batching” of bitcoin transactions—the sender and receiver both contribute inputs to a transaction, “breaking” common blockchain analysis heuristics.
“PayJoin is the most basic way to make a bitcoin transaction where you introduce interactivity. Instead of just the sender, both sender and receiver put inputs into the transaction.” – Dan (32:52)
This undermines the heuristic in Satoshi’s whitepaper that “all inputs come from the same person,” making surveillance much harder.
Cut-through and Real World Efficiency
Communication Layers & Avoiding Servers
Spam & Denial-of-Service
Plug-and-Play Tooling
Where Does PayJoin Fit?
Notable Quote:
“If there’s not privacy on the base layer, there aren’t privacy [protections] anywhere else. And I think that's where privacy is lacking the most.” – Dan (52:33)
Guy and Dan on Lightning’s Progress
“Thanks to everyone that's contributed. There's lots of people who... work on this mission and people don't even know about it. And a lot of the time it's for free.” – Dan (112:07)
Both Guy and Dan believe Bitcoin privacy is at a “pivot point.” With tools like PayJoin now mature and easy to implement, the remaining barrier is adoption. The episode leaves listeners hopeful, informed, and—true to Bitcoin Audible’s roots—equipped with the key concepts and history needed to understand and push for a more private future for Bitcoin.