Loading summary
Saifedean Ammous
Foreign. Principles of Economics My complete guide to Understanding Economics is now available in hardcover, audiobook and ebook from seifeddin.com, amazon and
Host of Bitcoin Standard Podcast
many more booksellers worldwide.
Saifedean Ammous
And now I am also teaching a course based on this book on my website seyfeddin.com Principles of Economics will run the whole academic year from September to June and will have a new lecture every two weeks, as well as weekly live online discussion seminars open to learners from all over the world and from
Host of Bitcoin Standard Podcast
all walks of life.
Saifedean Ammous
Whether you're a student, a professional, or a retiree, you are making economic decisions every day and this course will arm you with the wisdom of centuries of economists to improve your economic decision making. You'll also get a free book of Principles of Economics. If you sign up for the course, go to seifedean.com and sign up now.
Host of Bitcoin Standard Podcast
Hello and welcome to the Bitcoin Standard Podcast. Our guest today is known as Seed because he was the one who started the seedsigner project, an open source project for Bitcoin hardware, wallets or signing devices, and something that I believe is very relevant for my listeners to learn about today in light of the hack that happened with Coldcard over the last week. Now, needless to say, I don't recommend using ColdCard anymore. I've spoken about this on my social media repeatedly and I've published a few minutes of a podcast episode over the last couple of days urging people to migrate away from Coldcard because of the vulnerability that was discovered, which has resulted in the loss of a lot of funds. So over the last few days I've been frantically researching alternatives and trying to help people find alternatives. And I think Seed Signer is a good project for people to consider and Seed was gracious enough to accept my short notice invitation to come and talk about his project and I'm very grateful to him for doing that. So thank you so much Seed.
Seed (Seed Signer Project Founder)
You're very welcome. It's. It's a little bit of a treat to be here. You're. I think Bitcoin Standard is the only bitcoin book that I've actually gifted to Normies.
Host of Bitcoin Standard Podcast
That's a. That's great praise, sir. Thank you. I appreciate it. And thank you for everything you do with Seed Signer. So let's begin first of all by discussing Seed Signer. What is it and how did you get the idea for it?
Seed (Seed Signer Project Founder)
So Seed center is an open source DIY project that lets you build what is the functional equivalent of a hardware wallets using off the shelf, pretty simple, inexpensive electronic parts. We chose the characteristics of those parts really carefully. And our software suite is engineered in such a way that we leverage them to create from these simple things this pretty sophisticated secure device. And we're, we're a volunteer project. There is no seed center company. I love that you said project as you were initially discussing seed signer because a lot of people mistake it for some sort of business or a commercial product that you can, can buy. And while there are people out there in the world who build and sell seed signers, it is first and foremost a DIY project because that is a big part of the origin for some of the security assurances and improvements we think we offer.
Host of Bitcoin Standard Podcast
Yeah, no, I think this is a great idea and I think the value of that was really illustrated over the last week or so. The fact that you use essentially off the shelf devices that aren't specifically Bitcoin hardware, I think is a very valuable thing. So can you tell us more about why you make that choice?
Seed (Seed Signer Project Founder)
So there's a lot to say about that. Sometimes when you start with a project or an idea, the benefits or advantages of it aren't always immediately apparent. Right. When you start out and with ideas that end up being good ideas, a lot of times you'll back into some of the reasoning and discover after the fact that choices that you may not have intentionally made at the time were actually really good ones. The thing I'd start off by saying is that I think a lot of people don't have an appreciation for how much the hardware wallet industry is a centralizing factor with regard to Bitcoin cold storage or Bitcoin layer one storage, as we kind of learn very painfully with this coincide exploit that was found, like everyone who had one of their devices within a certain firmware range and hardware spectrum, if they were following kind of the default onboarding practices of using a cold card, ended up being vulnerable to this. And that puts a tremendous portion of the Bitcoin self custody kind of community at risk. And it's, you know, it gives Bitcoin a black eye, it creates uncertainty in the markets and it's just generally not good for bitcoin. And part of it is that this one company that was pretty popular was selling a thing and it ended up having unexpected software bugs in it. And now there's a larger problem. So what I'm getting at is, I think what I hope becomes a part of the conversation in the Bitcoin community is really thinking hard about decentralizing and diversifying Bitcoin cold storage and giving projects like ours There are other DIY self custody projects too. I'll mention Spectre, DIY and Crux as well as a newer one called Kern that is coming available. We all take this idea of do it yourself self custody and put a little bit of a different spin on it either with hardware or the software features or whatnot. But what I'd like to see is similar to mining. If you know, as you've been following Bitcoin for a lot of years, I'm sure you remember when there were these kind of situations where one mining pool started to gain a pretty significant portion of the network's hash rate. And when it broached that critical 50 or 51%, the kind of community alarm was sounded and people started redirecting hash rate to other places. I just think we want to be conscious of centralization with regard to people's cold storage because if any one manufacturer or one platform gets too much of that market share, if you will, like it creates these kind of huge vulnerabilities that put the whole ecosystem at risk. Now me personally with the cold card situation, just by virtue of my background and the way I think I always kind of was under the impression it was maybe going to be a three letter government agency or some sort of, you know, elite government task force or something that would be able to infiltrate, you know, a manufacturing facility where secure elements are made or somehow compromise the supply chain or that sort of thing. And what do they say? It's Brandolini's law, Never attribute to malice what can be attributed to carelessness I guess. So this didn't, this particular, didn't end up being a state level back door. This was unfortunately just, I think kind of sloppily architected code that created the current vulnerability. But as I said, it illustrates that whole centralizing vulnerability that I'm hoping that people are more aware of.
Host of Bitcoin Standard Podcast
Yeah, I think it's a very good point because the more successful a bitcoin hardware maker is, the bigger the bounty on finding a weakness in that code. And that's I think what's driving a lot of the interest in finding hacking. Because if you figure out how to compromise one of these devices, you're going to figure out a lot more. You're going to have a big bounty associated with it. I think that's really the key thing. And using off the shelf hardware that is not linked to Bitcoin, the really makes it much less likely that you would be targeted by these kind of approaches.
Seed (Seed Signer Project Founder)
Right, right. And something else I'd point to was we Try to be very conscious of our choices with regard to, you know, the options we present to users and the workflows and such. The seed signer will not use any sort of random number generator to create a key for you without some kind of input. The whole idea of a hardware wallet or random number generator providing people with a private key was always something I was not comfortable with. So ever since the outset, seed signer has been a you need to bring a key that you've either created using something else or use somewhere else. Or if you want to use the seed center to create a brand new private key, it's a great tool for that. But you're going to have to bring some sort of randomness to the table so that we kind of, it's kind of a guardrail that shepherds users into a process that should result in a more, a more secure private key. Now, are there ways that they could game the system? Like for instance, with Seed center you can roll dice to create a private key. Could somebody carelessly just enter 353535, you know, the 49 or 99 number of times that you have? Sure, somebody could do that. But we're really trying to usher people towards best practices. So either rolling dice or we have a really creative module where you can use entropy that's gathered through the seed center's camera to collect video frames and then take a photo. And the randomness that's in that input is what contributes primarily to your private key. Or we also support a method that I refer to as a Biphtheran lottery. And for less technical people, there are 2048 words that make up all of the possible words that can be in a seed phrase. And if you can imagine putting all of those words on little pieces of paper into a hat and then selecting at random words from the hat, not, not looking at the words and thinking which ones are clever or which ones go well together, but just truly randomly picking words out of the hat. That's another really solid approach for creating a private key that sidesteps this particular issue that we saw with cold card with regard to the random number generator.
Host of Bitcoin Standard Podcast
Yeah, and I think it's honestly, it was a bit surprising for me to realize that so many people were using the default random number generation with gold card because I just, you know, it's plastered all over the packaging that you should not trust and verify. So I thought, you know, the, you're trusting them, their machine with generating the random numbers. You should definitely be rolling the dice on this or you know, literally rolling the dice by figuratively not rolling the dice and not taking chances on that. But I guess people just choose the easy way out. And I think it's a, it's a massive wake up call because I think that the temptation with these hardware wallets is you don't want to tell people that, hey, you know, you need to use crazy hardware and you don't want to tell them that you need to do it yourself. It's so tempting to just tell them there is an off the shelf solution, but if it's an off the shelf solution, the more of an off the shelf solution it is, the more convenient it is, the more you're going to be introducing weaknesses that can be targeted and then the more successful it is, the more that you're going to be putting a bounty on finding ways of exploiting that weakness. And this really seems to be the undoing of Coldcard.
Saifedean Ammous
Now for a quick word from our sponsors. With fiat money constantly debasing, preserving your
Host of Bitcoin Standard Podcast
wealth isn't an option or luxury.
Saifedean Ammous
It's a financial and moral imperative. If you're familiar with my work, you know the only financial advice I ever
Host of Bitcoin Standard Podcast
give is to buy and hold Bitcoin for the long term.
Saifedean Ammous
This has never failed anyone. If you want to buy Bitcoin, I strongly recommend using Swan, a group of
Host of Bitcoin Standard Podcast
hardcore bitcoiners laser focused on making Bitcoin easily accessible.
Saifedean Ammous
While most scramble to react to each new crisis, Swan Private clients are already positioned in the only monetary asset with absolute scarcity, Bitcoin. Swan Private partners with families and institutions who share a principled conviction in Bitcoin as the foundation for multi generational wealth. With concierge service, deep expertise and uncompromising security, the Swan team helps clients exit the crumbling fiat system and secure their
Host of Bitcoin Standard Podcast
future in sound money.
Saifedean Ammous
Today, Swan Private serves more than 5,000 high net worth clients who have purchased more than $4.5 billion of Bitcoin and
Host of Bitcoin Standard Podcast
put it into cold storage.
Saifedean Ammous
If you're ready to move beyond the false promises of fiat, start your long term bitcoin strategy@swann.com safe.
Seed (Seed Signer Project Founder)
I think there's some really important nuancer lessons there. What these countries or companies rather really profit from doing what their business model is, and it's not a bad one, is, how would I call it, like reducing friction with the process of doing Bitcoin cold storage. And sometimes some of these companies get carried away with providing the easy button to the point that people don't really understand the importance of what they're doing or they don't understand the risks or mechanisms of what they're doing. And I think that's, that is the case with a lot of these harder wallets is they want to market, they obviously want to provide marketing that is very reassuring to users and projects a high degree of security and yet at the same time, ease of use. And I think the truth is that sometimes those two things are just not compatible. Like if you want to learn to defend yourself in your home without having to contact the police and wait for someone with a gun to show up at your house, you are going to need to get a little bit dangerous and buy a gun of your own and learn how to safely shoot it and learn how to secure it, how to clear jams and how to clean it and maintain it and that sort of thing. And it's a higher level of responsibility. And while the hardware wallet industry likes to obscure away a lot of the complication and in some ways there are some benefits to that. But if you obscure away too much of the complication, you take away the benefits. Like a great example are seed phrases. And this is true of almost all of the hardware wallet companies, maybe with the exception of bitkey, because they've discarded seed phrases. But the typical onboarding user flow is that you take the device out of the box, you either connect it to a USB port or powered on, it has a battery inside or whatever it is, and it comes on. And the very first thing the device has you do is write down these 12 words, write down these 24 words. People obediently, they're nervous. It's a high stress situation and they do that and they write the words down. But really, because they don't understand what those words represent or what they're safeguarding, a lot of times they take that business size card that they've written the words on and they'll store it in the same box that the hardware wallet came in. Right with it. And so if someone were to get into their gun safe at home or their safe deposit box at the bank or wherever they're deciding they might keep their hardware wallet, I mean those, those words that they wrote down but didn't understand what they were doing, those are the keys of the kingdom. And so just making it too simple of a process without educating users on the importance of some of the things they're doing, I think is what can create.
Host of Bitcoin Standard Podcast
Yeah, this definitely seems to be the case here. I think it's surprising that so many people were just going with the random number generation. I was, but that's, I guess Part of the appeal of buying an off the shelf solution. And you know, the thing is I, before getting into hardware wallets, I, I was living in Lebanon and I set up my wallet using an offline computer. And that was, I mean it sounds, honestly looking back now, it sounds so easy because it really is not difficult. I think there is, you know, that you want. It's, it's not cool. I guess it's not difficult, but it's not cool to say that you got an offline laptop, you took out the wireless connector from it, then you started it, you generated the keys and then you destroyed the laptop and destroyed the hard drive and destroyed the disk and destroyed the memory and destroyed it piece by piece and discarded it into different trash bins with high levels of paranoia. I mean, it's a lot easier than trusting somebody else's random number generator. And I think the key thing is. Yeah, go ahead.
Seed (Seed Signer Project Founder)
Some people might think that's very cool, but it's not something that we're realistically going to get a lot of people to do in terms of wasting a whole laptop and stuff. But I, I was kind of smiling when you were saying that because I, you know, in the early days, 2014/ish like that, that mirrors a very similar process to what I did with. There was a website slash open source project called bit address.org back then that
Host of Bitcoin Standard Podcast
allows the one I used.
Seed (Seed Signer Project Founder)
Yeah. And I bought an inkjet printer that didn't have any WI FI capabilities and it was just USB connected. And that printer still to this day sits in my basement even though those keys have been swept a long time ago. But I never use that printer for anything else. But it was, it was a similar. I didn't destroy the computer because I put background in forensics. So I maybe had a little bit more informed understanding of like what was safe and what wasn't. But yeah, that was almost like a rite of passage back then.
Host of Bitcoin Standard Podcast
Yeah. And you know, honestly, I think the, the fact that you can just do it so easily is a good reminder that these hardware wallets, they're not magic. They're not doing something that's really, really difficult. It's a very, very simple piece of software. You know, the bit address software is only a few kilobytes, I think to download onto you a USB which then you take to the offline computer. It's a very simple software. And the bit address1 is something that's been tried for. What is it now? I think it's been 12 years that they've had it out, maybe more. I think it's been there since before 2013. I think they upgraded it in 2013, added better entropy, and, you know, their entropy has held out better than Coinkite's entropy. So far. I've not heard of any breaches of that one. But really, it's a very simple process. And I think the difficulty is in not in the process itself, it's in securing the process. So really you can fix it with paranoia. And you're not going to get people onboarded by telling them, hey, just use a laptop for once. But you know what? Laptops are cheaper than the hardware wallets. You could just go on ebay, get a used laptop for 35 bucks, and you can use it and you can, you know, if you want to be extra paranoid, you can take out the wireless component because then you know that there's no malware that's transmitting anything. But realistically, nobody's going to put a malware on a laptop that was made 15 years ago in anticipation of you buying it off of eBay 15 years later and then generating private keys and them having some highly sophisticated software that transmits it. You get the cheap laptop and then you remove the WI fi even, you know, by being extra paranoid. And then you can even destroy the laptop and not have to worry about somebody cracking into it and finding a way to get the data back. But I guess what I'm trying to say is that it's actually a very simple thing. And trying to escape the just the courage it takes to do the simple thing is how you end up taking shortcuts that end up creating the problems. So Seed Signer is a project that essentially goes back to the basics of doing it, but doesn't use commercial hardware that's produced off the shelf.
Seed (Seed Signer Project Founder)
Yeah, I was going to say two things. One is that this, like, proverbial laptop that you operate offline is really what the Seed center is. The heart and soul of the Seed center is a single board computer, which is actually a very similar architecture to a common laptop or desktop computer. But it has some unique characteristics in that it does not have WI Fi, Bluetooth, or any sort of other wireless communication protocols that are baked into it. So it becomes this naturally very isolated, secure environment where you can create private keys and work with private keys. And so with that Raspberry PI zero single board computer, the very specific version that doesn't have WI Fi or Bluetooth, or you buy the version that does have it, it's actually nominally simple to pull one component from the Circuit board that shuts both of those off. But we pair with that a camera. And the camera is used to read information into the seed signer. And then on the other side of the device, we put a display and some controls. So really, this little device, its only way of talking to the outside world is not even through usb. USB connections, by virtue of my background in forensics, always made me uncomfortable when it's not as much the case now, but in the earlier days with Trezor and Ledger and some of the other ones that emerge after that, they all relied on this USB connection that always made me uncomfortable. But anyhow, a seed signer, the USB port we use to power it, it doesn't even carry data, so there's not the risk of data moving through the cable there. And as I said, it's isolated from WI Fi and Bluetooth. So the only way it can talk to the outside world is with the screen and with the camera brings in data through the camera, and then with the screen we can output information. But the other thing I was going to mention is that the conventional hardware wallet industry has kind of. I don't know whether this was intentional or unintentional, but sort of combine these two basic functionalities into this one device that it doesn't always make sense to have them, to have the same device doing them. And the two functions I'm referring to are seed storage and then the actual generation of the cryptographic signatures that are necessary to spend the money. So seed storage, you know, digital seed storage is more about saving a digital copy of the private key and then creating some sort of access controls that prevent someone who might get their hands on your device to be able to easily access that private key without, you know, a pin code or some sort of other information. But what we've done with seed signer is another intentional feature of the device is that when you power it on every time, other than settings you may have optionally saved, the device doesn't know anything about private keys you previously used. It doesn't know anything about transactions you've made or anything that you've done. So the friction is that every time you turn it on, you have to input a seed into it, usually one that you've already created that has been used to set up a wallet. Maybe you want to make an occasional spend from that. Got sidetracked a little bit there. But as I was saying, so when you power it on, it doesn't know anything about previous transactions. You either create a new private key or load a private key and make a spend. But when you're finished, you remove power from the device. And this is kind of a computer science principle that we used when I was doing forensics. And the device is operated in what in computer science terminology is called stateless, a stateless fashion. And all that means is that it's a fancy way of saying that information is not preserved on the device. You use the device in a certain way such that information is not preserved. The way that we manage this is that our entire software stack is running in random access memory, or what people refer to as ram. And the nature of RAM in a traditional computer architecture is that when you remove power from it, it's what they call ephemeral, which means that after power is removed, the electricity is what is keeping all of the bits and bytes in the specific places that they are while you're operating it. But when you remove that electricity, everything in RAM resets in terms of its data into a kind of natural starting point, typically either all zeros or all ones. And so with the seed signer, because our software is running in ram, when you remove power, it resets the device such that if someone were to steal your seed signer, they haven't really gotten anything because there's nothing preserved on the device about your keys or how you've used them. So with our model, it kind of de emphasizes the importance of that device. Now, with seed signer caveat, because it is general purpose hardware, it will run anywhere, any kind of software that you load onto it. So the user is responsible for ensuring that they've downloaded authentic software, verified that it's authentic, and running that software on the device, it's kind of like if you use a knife to cut up vegetables, you're going to have to have a certain degree of proficiency, or else you're going to end up getting stitches or losing a finger. With seed signer, users do take on a certain amount of responsibility because it's a powerful tool, but it is not something. There's been this unfortunate narrative that I think was started by Peter McCormick several years ago that whenever I heard Seed center come up in his podcast, he would always use the words too technical. And it kind of created this perception around seed center that it's only for nerds or people who tinker with hardware or people who are, you know, paranoid cryptographers or something like that. And it will require you to increase your knowledge and your skill set in a really not a huge way. There's just a few things you have to understand and learn. But it does put more power and responsibility into your hands, such that when you are doing bitcoin cold storage, you can do it with more confidence. Because the way that we guide people through the process, they just understand more about what they're doing and they're more comfortable such that, you know, if that device were to stop working, they would be a lot more comfortable recovering access to their funds from the source material of their wallet, which is their seed phrase or their private key. A lot of people, if they went to make a bitcoin transaction and they, they went to power on their Trezor and there was a sad face on the screen, or their cold card said bricked or something like that, like they would have a lot of anxiety because they really wouldn't be confident that they had access to their funds. Because there's, as we were talking about before, so much of this complication has been obscured away. But seed signing users, just by virtue of the skills you need to acquire and the things you need to learn to use it, can hold bitcoin with a lot more confidence. The other thing I'm kind of getting too circuitously is that other function of hardware wallets. The signing function is something that is separated from seed storage. With seed signer, we really put the emphasis on the analog copies of your keys. Because even with a hardware wallet, I mean, digital devices fail suddenly, irrecoverably, and often without warning, such that if you don't have your seed phrase written down on the card or stamped in the metal or something like that, and you go to use your hard wallet and it's bricked like you're not getting your money back. So everybody pretty much understands that they need to keep some sort of analog copy of their seed phrase because the importance of the device is de emphasized. With seed center, we don't attempt to secure that digital copy of your private key. It puts a lot more importance on the analog copy of your seed phrase or multiple seed phrases were kind of a multisig first project. You can use a seed center with a single sig wallet. But we really try to encourage and make multisig as easy as possible for people. But we really force people to focus in on those analog copies of their keys. Because with multisig, if you're using conventional hardware wallets, so you've got the digital copy of the key on the hardware wallet and then you have the written down words or the stamped in metal words. Obviously, as, as we talked about before, it's, it's not smart to keep those in the same place. So even for a simple two of three multisig, you're suddenly looking for six hiding places, one for each of the backups and then one for each of your hardware wallets. And so we just really try to compel people to think through their security, to think through where they're going to secret that seed phrase, where they hide it, where they secure it. Is it in a gun safe at home? Is it in a safe deposit box? Are you using multisig if you're worried about the seed being disclosed? Are you using a bip39 passphrase also to secure your seed? How many signers are in your quorum? If you're using multisig, are you hiding in your grandma's attic and a tree in your favorite field? The power of multisig was something that I have my own Bitcoin journey. But when I was revisiting my personal security setup in, I don't know, 2018, 2019, multisig was just starting to get to the point where it was no longer Bitgo and institutional custodians that had access to it with Spectre Desktop, and then following that with Sparrow, multisig suddenly became accessible to, really anybody who was willing to lean in and learn it. And so we haven't talked a ton about my career, but I was a law enforcement officer for 15 years, and uniquely for 12 of those years, spent my time in a digital forensic lab, working primarily investigating child exploitation crimes, but basically taking apart cell phones, computers, hard drives, and all of that, and trying to recover data from them to see if information on them supported or refuted a particular allegation. And that gave me a really unique perspective on some of the technical aspects of Bitcoin security, but also some of the more meat space aspects of Bitcoin security. So I, as a part of my job, help execute search warrants at people's homes and businesses. And as probably most people know, you walk into a residence with a search warrant and you have some pieces of paper from a judge that give you a very limited search of scope in terms of where you're physically allowed to look, what you're allowed to look for, and that constrains it to that residence. And I immediately recognize multisig is this huge asymmetric advantage to defenders of Bitcoin, whether it's from just common petty thieves, you're trying to defend your Bitcoin, or truly making Bitcoin way more seizure resistant as a form of money. But this multisig turns it in from, you know, someone from the Government likely has to come into your house and find something that's very obviously recognizable as a hardware wallet, turns it into this potentially global hide and seek game where they don't know how many things they need to find and they are going to have to work really hard to figure out if they can, where you've hidden them. So I've probably bladder on quite a bit here. But the key part of that last is the power of multisig is really underappreciated, I think among your average bitcoiner in the bitcoin community. And it's not as complicated as a lot of people try to make it out to be. There's unfortunately a lot of FUD around multisig and the complexity and the ability for the average person to do it. Most people I talk to have done it like after they understand the ins and outs of it and they've set up a wallet and they've signed transactions and then they've deleted the wallet and had to recover it from either a backup or the original keys. Like it's, it's not that complicated. It's something that most people can grasp. But I, I've said a lot, I'll let you dig deeper. Redirect as you'd like.
Host of Bitcoin Standard Podcast
Yeah, no, there's a lot to discuss there. I think I, I think you're absolutely correct on the idea of trying to make the keys physical and analog rather than digital because it's just, it's closing up so many avenues, so, so many potential avenues of attack for, for potential attackers because information that is analog is just so much slower and so much harder to access. And continuing to hold on to the physical hardware wallet, I guess, can be a vector of attacks. Then you know, they get their hands on it and they manage to know a pin, then they can enter it. But the, you know, the physical seed is more difficult to exploit, particularly if you distribute it over multisig, as you mentioned. And I think this is really one of the appeals, you know, now looking back, I'm overcome with nostalgia to the old bit address and smashed laptop thing because that left the keys truly analog and the keys were never on a, on a, an Internet connected computer. And this is really one of the most mind blowing things when you're explaining bitcoin that you could get an offline computer that never joins the network and you generate the address and the private keys and then an online computer can send money to the address that you generated on the offline computer. It's actually truly amazing. You can't join any network on earth while being offline. You can't join Facebook or Google or your cell phone company without connecting to them. But with Bitcoin you can do it. You can set up the wallet on an offline computer and then that's it. In a sense, the addresses all exist, they're all out there. Bitcoin is like this giant cloud Swiss bank safety deposit. And you just need to figure out the password for any one particular bank, and then once you have the password, any one particular box, and then once you have the password essentially, or the private key, then you can just send to it. So if you figure it out, you can do that on an offline computer and then online computers can send to it. So I think that's really a powerful tool to use in your quest for security and in your pursuit of paranoia, which you can never have too much of in this world, is to just try and keep the information off all digital devices. You make it on one digital device and then you don't keep it there. And I think this is a nice thing about destroying the old laptop, and it's a nice thing about the seed signer.
Seed (Seed Signer Project Founder)
And I think people intuitively, in terms of mental models, understand secrets and the importance of keeping secrets and, and they understand the importance of certain physical objects that, that are important to their security, like a house key, like a Bitcoin privately private key that is stored in analog form kind of as both of those things at once. It's a secret that you want to make sure you don't tell anyone or doesn't get out of the world. And being analog, it's a physical thing that is, that is storing that secret, persisting it into the future. Yeah, I think that's a constructive way to think about it. It's just kind of the magic of asymmetric key cryptography is something that our feeble minds can't really wrap around and almost seems magical to a large degree with what you were discussing about how you can create this offline secret and still use it to receive money from anyone in the world on this distributed network.
Saifedean Ammous
Now for a quick word from our sponsors. The Bitcoin Standard Podcast is brought to you by the safehouse.com, my independent publisher and bookshop, selling the best Bitcoin books in high quality cloth hardcovers built to last for generations. Most books these days are pretty fiat. They're flimsy and they fall apart quickly. And I did not want that for my books. So I set up the safe house especially to provide you with beautiful, long lasting classic cloth hardcovers you can proudly pass down for generations. You can get copies of my three books, the Bitcoin Standard, the Fiat Standard and Principles of Economics. And you can also get copies of Lyn Alden's Broken Money, Parker Lewis Gradually Then Suddenly and Matthew Lishiak's Fiat Food, to which I contributed a few chapters. We now offer bulk discounts so you can buy books for yourself and for the friends and family you'd like to learn about bitcoin. Buy any two books for $50, any five books or more for $20 per book and for more than 50 books it's only $15 per book. Go to the safehouse.com thesaifhouse.com where you can get all of these books in high quality cloth hardcovers delivered worldwide and get 10% off for paying with Bitcoin. This podcast is also brought to you by the Bitcoin Way, your professional Bitcoin IT team offering you personalized, secure and comprehensive solutions for every step of along your Bitcoin journey. The Bitcoin Way offer live concierge service to guide you with your Bitcoin cold storage, running your node, privacy best practices, inheritance planning, corporate strategy and multisig solutions. They don't touch your coins. They guide you through the process of acquiring your coins and securing them. If you'd like to make your setup safer and more reliable, book a consult with them and see what they have to suggest. If you want to give someone the gift of Bitcoin, get them this professional service that will ensure they start off knowing exactly how to manage their coins
Host of Bitcoin Standard Podcast
and not lose them.
Saifedean Ammous
Go to thebitcoinway.com and start bitcoining more confidently.
Host of Bitcoin Standard Podcast
Yeah, no, absolutely. So I guess the question here is how confident are you that there are no ways of hacking into your Raspberry PI to get the information from it once that information has been removed from ram? Are there some super coders somewhere in the world who have the potential to figure out how to get data from the Raspberry PI?
Seed (Seed Signer Project Founder)
You think so? There are. In security there are no perfect solutions. There are only trade offs with Raspberry PI. In terms of memory attacks, it's really something that's only done in a lab environment. But if you can get to a laptop or a Raspberry PI or some sort of microprocessor based computer and you happen to have liquid nitrogen and you freeze the ram, you can persist the data in there as long as it's kept cold. This is obviously one of those James Bond type scenarios that doesn't apply to the average person who's, you know, saving with Bitcoin in their home. So it's, it's something that's come up, but it's kind of easy to cast aside, so.
Host of Bitcoin Standard Podcast
But you have to use the nitrogen while it's on, right?
Seed (Seed Signer Project Founder)
Right. You have to have access to the machine while it's on. And there are actually academic papers that have been done about this, like kind of forensic angle of attack. And it's generally considered that within 60 seconds of a computer being turned off the information, the RAM is pretty much a lost cause.
Host of Bitcoin Standard Podcast
Okay, that's good to know.
Seed (Seed Signer Project Founder)
There, there are some esoteric attacks that certain individuals who have brought up that there could possibly be some electromagnetic radiation that is emitted by the processor. That if someone was in, you know, some enormous van parked in front of your house and had some sort of satellite or data collection thing that was probably bigger than the van itself, they might be able to capture some of these radio magnetic waves and interpret some of the computing that you were doing. But this is really all kind of like science fictiony stuff. If, if you have someone that's in a van outside your house and they're from the government, you have bigger problems than what, like a hardware wallet is probably going to be able to solve or that even seed center is going to be able to solve. And the other thing is like, if someone catches you while you're using the device, they would be, instead of using some sort of advanced forensic data recovery technique on the device, they would be better to just hit you over the head until you gave them the private keys that you were obviously had nearby while you were using the signer. I don't want to laugh this off too much because there is one very important point to make is that how do I, I kind of joke about this sometime in that I'm old enough to remember that the ability to run arbitrary code on a computer was a symbol of freedom rather than vulnerability. So before, before it became such that you had to jailbreak everything to be able to take total control of the device, like with iPhones and everything else these days. As I said before, a seed signer is built from off the shelf parts and we do not have any kind of software authenticity assurance built into them. That is one thing that I have to say, the hardware wallet makers have done well with the hardware set is that if you are tricked into downloading a bad firmware update, you get those emails that say, download this new update for your ledger or something like that, and you didn't make sure it was a good link or something the hardware will reject, most likely reject bad firmware if it's not vouched for by the manufacturer. Because with Seed center using off the shelf parts, you become the authenticity assurance mechanism. It's not a complicated process, it's not something that most people can't master. But when you download our software, you need to both hash it and then check to make sure that the hash of the software matches signatures that we've released cryptographically when we publish new releases. I know it sounds technical. It's actually just two or three commands from a command prompt or Sparrow Wallet, if you're familiar with Sparrow. They've actually automated the process that you can use that as a tool to verify the integrity of software binaries. Because if you do not verify your software, there are some attacks that could cause a loss of funds with a seed signer. Most notably, Hopefully I'm not going to blank on it, it'll come to me in a minute. But there is a type of exfiltration attack whereby manipulating nonces that are used to sign transactions portions of your private key can be leaked through the normal transaction signing process into the blockchain and then obviously somebody would be listening for those. Dark Skippy is the name of the most efficient version of this particular type of attack and haven't seen it the wild. As long as people verify they're running authentic software, it's a pretty solid security model. But I have to be real about, you know, you have to be willing to take on the responsibility to make sure you're not being tricked into downloading software that's malicious from a bad source and then putting it onto your signer.
Host of Bitcoin Standard Podcast
I think one major improvement in the security would come from the fact that you should treat the bulk of your stack as it starts growing. You should treat that as like a saving account and you shouldn't be spending from that. So you should probably think of it in terms of having the highest level of security for private keys that you store your wealth in that are not connected to the Internet and have never been on an Internet connected machine. So you generate them using an offline computer or a seed sign or something like that. And then you use them to sign only very, very rarely. And when you use them to sign, you know, maybe it would be worth it then to just use a brand new machine with, with software that you've tried and then, you know, you don't use that frequently so that you can, you can have the frequent use tied to a smaller Stash, that is when you're, when you're exposing those keys frequently to that machine. There are more occasions for somebody to find a way to hack into this. So it's best to not have all of your stack tied to private keys that are being sent all the time. Is that something you guys incorporate?
Seed (Seed Signer Project Founder)
Yeah, that's. That's an excellent point and it relates to what I was thinking to say earlier. So we all own bitcoin and we think of probably a magic number in our head, which is the amount of bitcoin that we own or would like to own or something like that. And we tend to have this put all of your eggs in one basket kind of mental model for storing bitcoin. And what you're saying is very important that I usually encourage people to think about it in like terms of three buckets of money. And one bucket of money is like a spending wallet that might be similar to the wallet you carry in your purse or in your pants. That is what you would use to buy groceries or if you go to a bitcoin conference and you want to buy a T shirt or something else and you want to pay with bitcoin, that's. That's kind of what that. Or you go to Steak n Shake, whatever it is. That's kind of an everyday spending wallet. And you wouldn't want to carry more in that wallet than you would be comfortable carrying in the wallet that you have in your purse or your pants. So just a few hundred dollars probably, and if you lost it, it would suck, but it wouldn't be the end of the world. I also encourage people to think about a medium sized bucket, that is for bitcoin purchases that you wouldn't be comfortable carrying around out in public, but you might still be inclined to make, you know, a few times a month or something like that, one or two times a month. So maybe one or $2,000, depending on, you know, I'm thinking in first world numbers, but something that, when you want to make a larger purchase, a largest purchase, let's say like you want to buy a TV and you want to pay with bitcoin or you want to buy a new hardware wallet because you're considering using multisig. And you might pay for that with bitcoin because it's a more private way of paying for it or whatever. But this medium sized bucket of money is kind of like a checking account where you have some access to it, but you kind of keep that. Most people keep their checkbook at home a lot. Some people Carry it around. But usually at home you're writing a check and then you have a savings account which is like the, you know, I dca into this in bigger chunks. And this is what I'm going to use to buy a car for my kid when they turn 16 or to help pay for my son's college education or when, you know, if bitcoin goes to the moon, what I'm going to use to put a down payment on a house or whatever it is like that, but with that bucket of bitcoin that is for those larger rare spends that's really basically akin to your life savings. That is where Seed center really shines for the, for the checkbook sort of bucket of Bitcoin. I actually think harbor wallets work really well for that use case in that they keep your private keys handy and at a close proximity, but they put a reasonable amount of access control restrictions around them such that if someone got access to that private key stored on no hardware wallet, it would at least take them probably a little bit of time to get to where they could get access to the money. With seed signer, especially if we're talking about multi sig, that's for those, those spends that you, you may only be making 1, 2, 3 spends a year and maybe that's to consolidate UTXOS or it's one of those medium to large size spends that, that you want to make or it's just for, you know, key checks. I, I every, every once in a while, you know, I will travel to where my private keys are and sign a transaction that I may or may not broadcast. But I just want to reassure myself that I still have access to the keys that I need to control the money. So in that last use case, especially if multisig, that is where seed center really shines. One other thing to mention about that last use case, especially with multisig, is that there are kind of two ways that you could do multisig with a seed center. One way is where all of the keys in that multisig quorum are analog keys that are compatible with Seed center and that you can use with Seed Center. And you use a seed center to create the keys and set up, you know, the entire wallet. And then the other way to do it that is kind of the best of the best practices is a multi vendor multisig. So that's where you take a seed signer and combine it with a Trezor and then maybe a bitbox 02 or a jade or whatever you want to pick and you create a two of three or three of five, whatever quorum you decide. But the advantage of that, the really important part of that is, as has happened with Coldcard, if some sort of critical vulnerability is discovered in one of those hardware or software stacks, or if one of the devices is compromised, someone with personal knowledge of your favorite PIN gets access to it, or it's stolen from a bank deposit box or a burglary or whatever it is. With the multiple different hardware software profiles, you get the resiliency of the multisig in terms of not having the loss of one key being a deal breaker for you. But you also, with the multi vendor approach, get the advantage that if there is some sort of critical vulnerability that was found in any one of those Bitcoin storage tools, including seed signer, like maybe you got tricked into loading bad software on the thing, if it's just one key in your quorum, then it's not a deal breaker in terms of losing your savings.
Host of Bitcoin Standard Podcast
Yeah. And so would you say the same would apply if you used syntax seed signers, different seed signers with different software,
Seed (Seed Signer Project Founder)
you don't get that full protection because you're likely going to be running the same software, a very similar software on all of them. So if there was some sort of critical vulnerability in our code, which again, I feel like we have pretty thoroughly reviewed code at this point, we've been around for several years, but if there was some sort of deal breaker in our code, if you were using a seed signer to manage every key in the quorum, you would be more vulnerable than if it was a multi vendor, multi sig solution. That's kind of, we can talk about time locks, even though that's not really my forte in terms of knowledge. And that's maybe the next thing with regard to Bitcoin cold storage. But that aside, the multi vendor multisig is kind of as strong of a, in my opinion, operational posture you can get into because it does mitigate any sort of unknown unknown with regard to vulnerabilities in the devices. And that's exactly what this cold card thing was, was kind of an unknown unknown that we're at a unique point in history right now with regard to computer science with the rise of LLMs and their ability to ingest and analyze tremendous amounts of information quickly. You know, if smart programmers had kind of gotten pointed in the direction of this vulnerability, my sense is that they would have found it without too much trouble. But with software projects, there ends up being technical debt and complexity that humans have trouble keeping track of. And that's what these AI computers are so much superior with. We're in kind of a reshuffling of not just Bitcoin security, but the Internet and broader information security right now because of AI and how it's breaking things.
Host of Bitcoin Standard Podcast
Yeah, no, it's absolutely mind blowing to think about the implications of this because there's a lot of crappy software out there and a lot of the AI processing power to go over it. So can you give us more of your opinion about why this Cold Card failure happened and how it happened
Seed (Seed Signer Project Founder)
in terms of the timing? I don't want to. So I used to be an expert witness in state and federal court very frequently. So I'm very comfortable backing off when I feel like I might say something that was inaccurate or beyond my depth. So I'm. The vulnerability in layman's terms, the hardware was on board to effectively create random numbers and create private keys, but the implementation of the software over the hardware was not adequate or correct such that it took advantage of. Of the capabilities in the hardware. That is my understanding of kind of the high level architecture of why the vulnerability exists at some point in the past. There's a lot of history to Coinkite's licensing and their software. It's pretty widely known that Coincite was a fork of Treasures code, you know, several years ago, pre2021. I don't remember when the first Cold Card came out. And then Coin Kite and Coldcard were registered as open source for the time after that when they leveraged Trezor's code to get going. And then at some point, Foundation Devices created a company and started to develop a product. And because Coin Kite's code for Coldcard was permissively licensed, they were able to, they were able to use portions of Cold Cart's technical stack as a kind of springboard to launch a product. That did not make Rodolfo Novak, who is the, I don't know if he's the title, the president or the CEO or what his title is. He's the principal operator of Coldcard. He really did not like that because it, I guess, enabled foundation to build a business and profit from work that they had done. So they started rotating licenses and I believe creating some of their own libraries to get away from the code they'd been using with Trezor. And it's my understanding that during that migration to the newer libraries, this particular vulnerability was either created and then missed or somehow occurred. And so that's why it goes back several years, because this ineffective implementation of the random number generation feature of the hardware. That was just a part of the migration that happened. Hopefully I'm, I'm making some degree of sense about all this.
Host of Bitcoin Standard Podcast
Yeah, this seems to be the same impression that I have of this story. And I think it's a, it's a, it's a very fascinating point in favor of open source, because I think the, the issue here is that by moving away from purely open source, then coinkite essentially discouraged people from reviewing the code because they couldn't build on it. And so if it continued to be open source, you may have gotten several more companies that have copied it and used it, but you would have gotten a lot more reviewers.
Seed (Seed Signer Project Founder)
You would have gotten a lot more reviewers. And there's actually two sides of that coin. There's just the natural incentives that come into play when software is open source and it's permissively licensed so that other people can use it. That, as you alluded, encourages other people to implement it in their projects and their products, and it encourages them to take a lot closer look at the code to make sure it's running as efficiently as possible and doing exactly what it should be and all of that. But then I have also heard anecdotally that in the past when issues were raised and in, with regard to cold cards technical stack, I guess I can diplomatically say that they were not super receptive to those concerns as they were raised. One particular instance that isn't very technical that comes to mind to me is that previous versions of the cold card made it such that we've talked about how you can create private keys with dice rolls, and it was actually possible with cold card to create a new private key using just one or two or three dice rolls. And this, it's a documented thing. You can find at least one story on Reddit where this happened, where someone who really didn't understand what they were doing created a new wallet with a private key that was the result of, let's say, just one dice roll. And immediately, as soon as they deposited funds into it, the funds were swept, you know, to some other wallet controlled by who knows what. And I wouldn't call that necessarily a technical failure. It's more of a user experience failure. Because if you're, if you're really trying to care for your customers, like maybe you overlook that when you were architecting the option set and you're like, people should have to roll a minimum number of times to create a private queue, ensure that it's secure. But when that guardrail was found to be missing, they still weren't receptive to the concern. It was more like that was just a stupid user and it's their fault kind of a thing. And so there's been this kind of just unfortunate pattern of unreceptiveness to legitimate concerns that have been raised.
Host of Bitcoin Standard Podcast
Yeah. But it seems to me, I'm struggling to quite get this story because it seems to me if somebody had the ability to wipe away the coins that you had that this user had deposited, then that seems to me like they would have known about this failure already. And seems to me like they would have wanted to use that for something more than just this one user. Right.
Seed (Seed Signer Project Founder)
It's kind of like the brain wallet problem. Like somewhere out there. I don't personally think like this, but I. There are people that think somewhere out in the world there's a dumbass who's going to create a wallet with a private key where they've only rolled the dice less than 10 times. And it's a known, you know, based on the, the, the derivation path that you use when you set up in the wallet. There's a lot of details and stuff, but if you use like a default derivation path, the very first deposit address is deterministic, so it's highly predictable. So what someone would just do is run a bot on the Internet that just looks at the blockchain and continually checks to see if there is any Bitcoin assigned to this particular private key or this particular bitcoin address that correlates with the private key that in this case was insecure because it was insufficient dice rolls. And so I, I'm not sure if that answers your question, but there's like, there are people who just like, you know, when brain wallets were a thing, like common passwords. If you created a brain wallet using a very common password and submitted bitcoin to it, it would likely very be be very quickly swept up for the same reasons, hopefully. I'm explaining that in a way that is accessible.
Host of Bitcoin Standard Podcast
Yeah. So I guess the idea here is that from what I heard is that because of this bug in the software, the randomness, instead of being some, instead of picking from some enormously large number beyond our ability to even comprehend, it was only picking out of 4.3 billion possible numbers. Is that correct?
Seed (Seed Signer Project Founder)
Or in this case only six possibilities. Because if you just roll dice once to create a new private key, there's only six possible number outcomes of that. You know what I mean?
Host of Bitcoin Standard Podcast
Yeah, but in. But isn't it also combining the dice roll with the device.
Seed (Seed Signer Project Founder)
Ah, I get where you went wrong. So in, in Cold card, and I should have been more explicit about this, you can use their internal random number generator generated entropy and combine that with dice rolls, or there is a feature whereby you can create a new private key that is purely the product of dice rolls. And what happened with the case I'm describing is where they used the feature that was just. I'm just going to use dice rolls to create a private key and I'm just going to roll the dice once. I know it sounds ludicrous, but this, it really did happen.
Host of Bitcoin Standard Podcast
Oh, I see. So he was not relying. So, so that would be completely unrelated to this bug then, because it didn't rely on the device.
Seed (Seed Signer Project Founder)
It's, it's unrelated. But what I would argue is that first of all that feature, my humble opinion, should not have existed ever in the first place. Because allowing a user to create a private key where the source of entropy is just one dice roll, that's something that's super easy to solve for in software and that you could just like enforce a minimum number of dice rolls to create a pirate key that the user is forced to, to enter. So in my opinion, it's, it's more of like a user experience failure to put like just reasonable guardrails in place so that people don't rug themselves. Like I. In the end, is it the user's fault? Probably. But could very simple things also have been done to prevent that from happening in the first place? Yeah. And when you're presented with that as a company, your first response shouldn't be like, stupid user, it's their fault. If you're a mature person, your response
Host of Bitcoin Standard Podcast
is more like, how do I make this stupid proof?
Seed (Seed Signer Project Founder)
Yeah, how do, how do I make it a little bit better so at least that dumb thing doesn't happen? Or you know, whatever.
Host of Bitcoin Standard Podcast
Yeah, yeah. You know, I think the I, I used Craig Ross Sparrow guide for setting up a Coin Kite, a cold card, and that just treats the dice rolling as essential. You gotta add the dice rolls. I think whereas I was looking only the last couple days, I was looking at the instructions in, in the Coin Kite website and it seems to basically say that it's more of an optional thing. I think this is, this is probably why a lot of people have used this because essentially they were trusting the device and that was being sold as, hey, this is good enough randomness, you don't need to waste your time rolling dice.
Seed (Seed Signer Project Founder)
And yeah, it's, yeah, yeah, it's two things. One is that, you know, they're trying to create the easy button, which is this very simple onboarding experience, and asking people to get out dice and roll, roll them, you know, while they're setting up the cold card is friction that maybe whoever was writing the documentation thought they wanted to downplay or say it wasn't absolutely necessary. So it's one is like that, that private company incentive to create the easiest user experience possible, which flies in the face of best practices. And then secondly, boy, I'm having the senior moment now.
Host of Bitcoin Standard Podcast
It's okay. The editor will get it out, don't worry. Yeah, we've got a lot of seniors on this podcast.
Seed (Seed Signer Project Founder)
There's the easy button factor and then there's also. What I was getting at is hubris. You know, there's this just, if you're being honest with yourself, there are unknown unknowns and you don't know what you don't know. You. I'm sure that if anyone would have asked Rodolfo Novak or somebody else at the company, is your implementation of the random number generation features of the hardware set that you work with solid? They would have said, yep, it's solid. But this is one of those cases where unknown unknowns that, you know, if you have some degree of a lack of humility about it, like, they can, it can come back to bite you. And so it could have been, you know, both, like, we want to onboard users and keep things super simple. And maybe it was, you know, a culture of a little bit of overconfidence about our implementation and, and this best practice of supplementing with dice rolls is just not necessary because we've, we've done this so well and it's just like, it's not necessary. Now, Craig Ra is an absolutely solid bitcoiner, and it does not, I've never looked through his cold guard onboarding, you know, guide or whatever, but it does not surprise me that he did not miss that detail. Yeah.
Host of Bitcoin Standard Podcast
And this is why, when I first heard about this, I did not imagine that there would be a lot of people affected by it. I thought it would be people's, you know, spending wallets that would be on this. But yeah, I, I, it's, it just makes sense that you wouldn't want to rely on it because the whole point is not to trust, like if you, if you're trusting them with a random number generator, I mean, there's so many attack vectors to that. The other thing is this is a company that's shipping so many different devices every day that, that somewhere in the supply chain or the mailman, someone could step in and compromise the random number generator. So even if it is a, even if it is a, an offline device, you're still having to trust the random number generator because it'll, it can produce seeds that can be guessable or it can just completely, you know, produce predetermined seeds so that you just send your money to these addresses that have, that are already set up as traps for you.
Seed (Seed Signer Project Founder)
Right? It depends on how far the supply chain you want to crawl up. But if you want to put on a tiny little bit of a tinfoil hat, like if we believe that Bitcoin is truly disruptive to the national economic order or the international economic order, and that some governments or some elite government agencies might be threatened by the existence of Bitcoin and that these agencies have a documented history of infiltrating both hardware and software supply chains, you don't have to jump very far to think, you know, is it possible that at some point we could see an intentional compromise? Everything I've seen with this cold card thing seems that it's just inadvertent and it was just like a poor implementation. But a real nation state attack on, you know, either low level firmware or the random number generation routine like that is something that could set Bitcoin back years, if not decades. Because in the fog of that attack, you know, that almost would seem like a, you know, either the cryptography of Bitcoin had been broken by, you know, who knows, either the cryptography is broken or maybe China finally found the new next level of computing that is able to crack, you know, sh, sh. Private keys. You, you just don't know. And it, it's, it's a vulnerability that could enable, maybe they're sitting on this for years and in a moment of global uncertainty when maybe we're on the edge of war or there's a war already underway and they want to create chaos in someone else's economy, just make, start making Bitcoin disappear from people's wallets or maybe even government's wallets or corporations wallets. Like, it's scary when you think about it. And that's why I go back to the necessity of beating the drum about diversifying the cold storage ecosystem with regard to it's not reasonable that I'm not naive and think that everybody's going to use a seed signer or even that maybe it never even makes it beyond single digits. So of, you know, the, the larger Bitcoin cold storage community. But like the diversity thing is Real and, and we need more viable projects, we need more viable companies, and we need more people getting back to like, best practices when it comes to creating private keys. For anybody that's watching this, when you initialize a new hardware wallet or a new signing device, you should never accept my opinion, a key from that device, you should always provide some sort of input that is unique and ephemeral and unguessable and something that only your access to a tiny slice of reality could create so that you get that true randomness that is, that is what creates a secure private key.
Host of Bitcoin Standard Podcast
Yeah, no, these are very wise words. And I guess, you know, the, the supply chain attacks are something that is worth keeping in mind. And for that I really think the, the, the old ebay laptop continues to be undefeated. Undefeated. And you know what, I'll, I'll just say one more thing because this week has really made me miss the old days. The old laptop is cheaper than a hardware wallet and it's got a proper key keyboard, then it's got a proper screen. So if you're using that for, you know, saving account, essentially the equivalent of your saving account stash, which you're not going to be using every day, you're not going to be spending from every week or so, then yeah, I mean, it's not very environmentally friendly to be destroying computers and throwing them out. But if it's 35 bucks off of ebay, then maybe it's not the worst thing in the world.
Seed (Seed Signer Project Founder)
Right? And it's interesting because I have heard more than one core dev or people who are deeply technical in the Bitcoin space who are very open about saying that they don't trust hardware wallets and they fully have wrapped their mind around the supply chain risk and how easy it would be to compromise something like that at the lowest level. And what I frequently hear from them is again, what you're talking about. Get a laptop, ensure it's offline, keep it offline and either put it in a safe or destroy it, you know, and that is what they're comfortable using. I mean, you can argue there's a lot of technical complexity in Linux and the software stack is much more complicated and you can't know what's there. But it's at the same time it's, it's, there's much less of an incentive to, you know, attack unrelated operation system libraries or as you said, a computer, that there's a minuscule chance that it's going to be used for some sort of Bitcoin related operation and that was created before bitcoin was even economically worth attacking to begin with. Yeah. Side note, the creator of bit address.org is an amazing bitcoiner named Peter, and I was super lucky to get to meet him. Point Biz is his nim online. He's public in that his name is Peter, but he's, I believe, a Canadian expat who has moved to Curacao. And he has created just the most amazing bitcoin community down there with so many. So many businesses locally there that are aware of bitcoin and accepting bitcoin and stuff. So I. Because we Talked about bit address.org, i feel a certain kind of kindredness with him in terms of, like, we went about it in different ways, but we both did it open source with general purpose computer parts. And when he produced bit address.org, that was something that was really desperately needed by the bitcoin community. And he just stepped up and did it, permissively licensed it, put it out there for free. It was a quality thing. And it was such a contribution to bitcoin that I don't think he gets credit for. So that's why I just want to kind of take that tangent.
Host of Bitcoin Standard Podcast
Yeah, absolutely. I also happened to meet him once and I was like a fanboy because this was really my first moment of getting the real power of bitcoin. Because before that I had been using just a bunch of phone wallets. And then I got into this and I remember thinking, this is powerful. And it lasted me for quite a while. And it. And it hasn't been compromised yet. Right. Nobody's found a way to break their randomness.
Seed (Seed Signer Project Founder)
At one point, I believe he told me, and this was very early, maybe in 2013, it wasn't broken, but he found a way to strengthen the entropy even more and did that. And as far as I know, like. Like bit address.org funds or SAFU.
Host of Bitcoin Standard Podcast
Yep. Yeah. From what I. The way it works for people who aren't familiar, it's. It takes the randomness from the movements of your mouse and from keyboard inputs. So you press a bunch of buttons and keep moving the mouse for 30, 60 seconds or something like that. And then it takes that randomness and it uses it to generate the seeds and private keys. And it's. Yeah, it's been working. I think there is again, it's the trap of wanting something to just be off the shelf, to be ready. That is what gets you. And it's really not difficult. I understood bitcoin a lot less than I do now, when I first did that, and it's actually remarkably simple. So, Peter, if you're listening, we're both big fans. I think he's on Twitter @btc now. I think that's his handle.
Seed (Seed Signer Project Founder)
Yeah, yeah. That's where he's primarily active.
Host of Bitcoin Standard Podcast
So.
Seed (Seed Signer Project Founder)
And like you said with the mouse, it's just a simple but very elegant solution to capturing randomness from, you know, the source.
Host of Bitcoin Standard Podcast
Yeah. See, it continues to work. And I saw he's working on some new project for multi seg. I think it's called Arctic or something like that. I haven't seen the details of it.
Seed (Seed Signer Project Founder)
We have. I have a little bit of a personal difference with that. He is a fan of people using mobile phones as harder wallets because they're kind of like similar idea to what you were saying that, you know, it's a device that maybe a phone that's five or 10 years old and has a low probability of having anything compromised on it. But with my background in forensics, I'm not super comfortable with using a phone given that the sole purpose of that device's existence is to connect the networks. And so you really have to lean hard into trusting the software that's loaded on the device because it's not practical to break it open and start disabling the network integration into the board. And for me, it's just too much of a mental leap to trust the software to keep the device isolated from the network, given some of the software supply chain exploits we've seen from, you know, sovereign governments and things like that. So I, I, he's very thoughtful about it and he can definitely steel man the case for it. It's just not something that I'm on board with.
Host of Bitcoin Standard Podcast
Yeah, no, I agree. Any more thoughts you have on cold storage in general, Advice for people or other projects you're working on or things related to Seed signer? Take your time.
Seed (Seed Signer Project Founder)
Yeah, yeah. So a couple of things. One is, even if you are not like drinking the Kool Aid about seed signer and you don't think it's something that you would want to use for cold storage, it is a heck of a bitcoin Swiss army knife to have around if you have some sort of issue. I've talked to a lot of people who it's for that moment when you go to update your firmware on your hardware wallet and suddenly it says it's bricked or you go to power it on and the display has expanded or the battery's expanded and it's broken the screen or something. Like that. Or I've also heard of people that had weird multi sig or signature bugs to where they could not get their hardware wallet to sign a transaction. But when they recreated that wallet in a secure way, of course, with seed signer, they were able to sign transactions and have the reassurance that they could move what money they needed to. So even if you don't want to use seed center for your wallet or you don't think it deserves a place in your quorum, I would highly encourage people just to get one and maybe just consider it as a learning tool because it really does teach you some things about the nuts and bolts of Bitcoin transactions and how they work. That even if you're still using a commercial hardware wallet, you will have a higher degree of confidence in your understanding of what is actually going on on that device and what it's doing. And you'll have the bonus of if you ever have a problem with your hardware wallet and you're sitting there looking at the paper card with your seed phrase on it, that seed signer is a tool that can, within a matter of minutes, give you access to your funds so that you're not freaking out, wondering how you're going to recover your money, or being tempted to sweep it to an exchange or use some dodgy tool that you're not familiar with. So like I said, even if it's not your go to tool, I think it's good to have it around. I created the project in 2009. It scratched a lot of itches for me, giving my unique background in digital forensics with some information. I have a management information systems degree too, so I have some information security sprinkled in there as well. And just wasn't comfortable with a lot of things about hardware wallets because I'd seen, you know, my job was to break into Android phones and iPhones. And I was fortunate in that the agency that I worked for had a good relationship with the FBI, with the Secret Service, and that we got access to some of the tools that they either internally developed or, you know, purchased from Israeli security firms or other security firms. And I got to witness firsthand the cat and mouse game in terms of when phones were these, you know, rudimentary devices that you flipped open and hit the seven key six times to get a lowercase l or something all the way into the supercomputers that we carry in our pockets. And every step of the way, that's been a cat and mouse security game in that Apple or Samsung or name another company will come up with a new security feature and maybe from my experience, for three months, six months, I wouldn't be able to get into that device. And then suddenly I'd get an update on one of my tools or there'd be a new product that was available that I get access to. And so with all of the money that Apple, Samsung, et al are able to spend on security, they still were not able to keep high level government agencies, and we talk about this a lot more, but they still weren't able to keep out for any sustained period of time. So just from a logical perspective, these tiny startups that are producing these hardware wallets that have a security budget that is literally, you know, in a couple orders of magnitude, if not less smaller than Apples, being able to produce a device that is just ironclad and completely. I had a lot of skepticism around the claims of hardware wallet companies. And so that was one of the things that brought me to Seed Signer and to rethink the model of, you know, if we're not going to try to build this super secure vault that protects your private keys from any attacker, maybe we flip that on its head and lean into the device just doesn't remember anything and you focus on multisig and the analog copies of your keys. But I want to emphasize that even though I'm the one who started the project, Seed Signer is a volunteer community effort that has been one of the most rewarding and inspiring sort of experiences that I've had, not just as a bitcoiner but in my life. So I first started paying attention to Bitcoin in 2013 when I heard about it at work and I went to Bitcoin Talk and went to Reddit and started learning. And I was a young father with way too much debt and I was looking for investments and so I started buying bitcoin and where your money goes, your mind goes. And I was deep into bitcoin culture during the let's talk Bitcoin Andreas Antonopoulos Deep bear market of 2014, 15, 16. And there was this just cypherpunk fu money. We're going to take the power to steal from everyone through inflation out of the government hands. Bitcoin is really, and I wasn't super early the party. Bitcoin was really this super cypherpunky thing. And then fast forward just five years. I was super blessed to be able to step away from my law enforcement career in 2019. And I kind of took a year just like goofing off and doing stuff and then finally stumbled into what became Seed Signer. And I had this longing for the 201314 era of people doing things because they were the right thing to do. And it was open source and it wasn't about corporations making money and getting startup, you know, investments and all that kind of stuff. And so that like that has been kind of baked into Seed Signer from the beginning. And within the first, I would say like six months of when I started the project in late, late 2020, I met three of the most amazing Bitcoiners. Two at the Miami Bitcoin Conference in 2021. And then just another guy randomly who found seed signer on GitHub who are the most based, amazing bitcoiners who have continued to volunteer just to keep building Seed center for the good of the bitcoin community because they love bitcoin and they're just like awesome people. And so to shout them out, they're Nick, Keith Mackay and another nim who goes by the name of Easy. It was an amazing UI UX designer who is like the ninja behind why Seed center has the polished, logical, super intuitive interface that it has when you build one. It's something that feels much more like a device that you would have bought after you have it assembled and working. We just have super great user flows and a graphically driven interface that is, you know, intuitive. And I get told a lot, it's, it's a better experience than a lot of the things that people would pay a lot of money for. So I just want to emphasize that even beyond those three, there are a ton of other bitcoiners who have jumped in and helpless Seed Signer with everything from helping us, you know, have a website that is responsibly maintained and looks nice to, to all of the code that goes into the code and the features that we've added over time and helping us think about how we can improve our security posture with the hardware. And then moving into the next chapter of Seed Signer is running on alternative hardware platforms which we're kind of on the cusp on. It's still a very vibrant active project that I am immensely proud to say is continuing to be developed in the spirit of open source permissionless, just like Freedom Money. And so I like, it never made sense to me just to kind of put a lid on this that you have this permissionless open source monetary network that anyone can join, but if you want to use it as a savings tool, the first thing that everybody's going to point you to is some overpriced product that was created by a startup with venture funds or whatever, something like that. Like why should I have to buy a proprietary, sometimes closed sourced, overpriced thing to save with Bitcoin when it's this open, permissionless monetary network? So we've tried to create seed center really in the spirit of Bitcoin and that's why it's not a product. That's why I've turn down venture money multiple times and that's why we continue. We, we, we don't have the development pace because we're volunteer driven, but it, it's outside of it being a great cold storage tool. Like it's an amazing community of people who build this. Not not just build this tool, but help each other. They make presentations. People who aren't technical and don't write code for a project make presentations at their local bitcoin meetup and help people build seed signers and teach them how to use them. And it's, it's just this, this phenomenon that I'm humbled by and proud of.
Host of Bitcoin Standard Podcast
Yes. Well, all power to you. Thank you for doing this. Thank you for continuing to work on it. And I know a lot of people are going to start looking at it a lot more seriously now because I think it's, it really answers a lot of the questions a lot that this recent cold card exploit raises. And I wish you guys all the best.
Seed (Seed Signer Project Founder)
I appreciate it.
Host of Bitcoin Standard Podcast
Cheers, man. Thank you so much for joining us.
This episode, hosted by Dr. Saifedean Ammous, addresses the recent catastrophic vulnerability discovered in the popular ColdCard hardware wallet, which led to significant Bitcoin losses for users. In response, Saifedean invites Seed, founder of the open-source SeedSigner project, to discuss decentralized alternatives for Bitcoin cold storage, the philosophy and security model behind SeedSigner, and best practices for self-custody. The conversation covers the risks of centralization, the dangers of convenience, multisig security, and the importance of analog backups in sovereign Bitcoin storage.
Centralization Risks in Hardware Wallets:
Quote:
“A lot of people don’t have an appreciation for how much the hardware wallet industry is a centralizing factor…when one platform gets too much…you create huge vulnerabilities that put the whole ecosystem at risk.”
— Seed ([03:57])
Hardware Wallets Attract Attackers:
Not a Company, a Project:
Security Design Decisions:
Decoupling Key Functions:
Encouraging Analog Backups/Multisig:
Quote:
"The more successful a bitcoin hardware maker is, the bigger the bounty on finding a weakness... Using off-the-shelf hardware makes it much less likely you’d be targeted."
— Saifedean ([07:55])
Problem with Relying on Device-Based RNG:
SeedSigner’s Approach:
Best Practice:
"You should never accept, my opinion, a key from that device. You should always provide some sort of input that is unique and ephemeral and unguessable…"
— Seed ([69:15])
Contrast with Off-the-Shelf Experience:
Easy-Button Dangers:
Quote:
“... It's not difficult, but it's not cool to say you got an offline laptop, took out the wireless connector, generated keys, destroyed the laptop. But it's a lot easier than trusting somebody else's random number generator.”
— Saifedean ([16:34])
Education and Friction:
Physical Seed Phrases are King:
Multisig Security Model:
Quote:
"Multisig turns it from... having to come into your house and find something... into this potentially global hide and seek game where they don't know how many things they need to find."
— Seed ([26:36])
Lab-Only/Dormant Threats:
More Likely Risks:
Quote:
"If you have someone in a van outside your house... you have bigger problems than what a hardware wallet is probably going to solve."
— Seed ([41:29])
Failure of RNG Implementation:
Quote:
"There’s been this kind of just unfortunate pattern of unreceptiveness to legitimate concerns that have been raised."
— Seed ([58:38])
Offline Laptops vs. Hardware Wallets:
Enduring Success of Bitaddress.org:
On Community & Culture:
On user responsibility:
“If you use a knife to cut up vegetables, you're going to have to have a certain degree of proficiency or you’ll end up getting stitches or losing a finger. With SeedSigner, users do take on a certain amount of responsibility because it's a powerful tool…”
— Seed ([21:51])
On multisig’s defensive strength:
“Multisig turns it into this potentially global hide-and-seek game…”
— Seed ([26:36])
On analog vs digital:
“Keys physical and analog rather than digital… closes up so many avenues of attack.”
— Saifedean ([33:58])
On convenience vs security:
“If you obscure away too much of the complication, you take away the benefits.”
— Seed ([13:37])
On open source and code review:
"If [ColdCard] continued to be open source, you may have gotten several more companies... but you would have gotten a lot more reviewers."
— Saifedean ([58:00])
On the enduring power of the basics:
“The old eBay laptop continues to be undefeated.”
— Saifedean ([72:17])
“We need more viable projects, more diversity, and more people getting back to best practices when it comes to creating private keys.… When you initialize a new hardware wallet…you should never accept…a key from that device. You should always provide some sort of input that is unique and ephemeral and unguessable and something that only your access to a tiny slice of reality could create…”
— Seed ([69:15])
Listen further for rich, technical insights and inspiration on reclaiming your Bitcoin sovereignty.