0:00 So we were just going to go three minutes back and forth. Three minutes you, you start off as the pro side. JW and Ty, three minutes. Three minutes you, three minutes them. Do that for like, you know, four or five rounds, and then take audience questions. 0:15 Okay, sure. 0:16 Do you think three minutes is too compressed? 0:18 I thought maybe for a... 0:23 If anything, I think three minutes is too long, but I don't really care. 0:29 Let's just do three minutes then. All right. Everybody ready? 0:34 Okay, sure. 0:35 The floor is yours, Paul, for the next three minutes. I'll keep time. 0:39 Okay, great. 0:41 So my name is Paul Sztorc. Many of you know me already. I've presented at many Bitcoin conferences, including Scaling Bitcoin, Building on Bitcoin, Consensus New York City, blah, blah, blah. 0:58 And I recently presented at Bitcoin 2021, this BIP300 idea that I've been working on for a while. 1:07 And I planned on... 1:12 Well, let me tell you the story about how I got to this point. 1:14 So in early 2014, I published this peer-to-peer blockchain technology called Truthcoin, which was this oracle system. 1:24 And it was favorably reviewed by a lot of people, let's say, including Andrew Postreau and Adam Back, people who are still popular today. 1:34 And Blockstream published a paper later that year, in October 2014, about this sidechains idea. 1:44 And I was like, oh, great, finally, because the oracle system was its own blockchain. 1:48 So I was like, well, okay, I'll use this sidechains idea to connect the oracle system to Bitcoin, and then people will be able to use it. 1:58 And that'll be great. 2:00 And that was this idea that they called the skip list in appendix B of this paper they wrote in October 2014. 2:08 And so I sort of finished developing Truthcoin, which is the oracle software. 2:13 And then I started reading through their skip list idea, and I thought that I could improve it in a couple of different ways. 2:21 So then I published Drivechain in 2015. 2:25 And then I got feedback from it at Scaling 3. 2:29 And then we worked on I Invented Blind Merged Mining in January 2017 at Construct. 2:37 And then that was all idea stuff, basically, that was like conceptual. 2:44 And then we worked on the code from 2017 to present. 2:50 So before then, it was just design. 2:52 And now there is code, and now there's a working Zcash sidechain. 2:58 So that's how we got to this point. 3:00 And then there has been a lot of back and forth on reviewing the design. 3:09 But now we've reached this point where Vake put out a call for anyone willing to debate. 3:15 And Weatherman answered. 3:19 So I'd like to hear what his complaints are, I guess. 3:29 Got anything else to say, Paul? 3:32 I don't really know. I'm more interested in answering the objections, I guess. 3:36 I just kind of rambled that off. 3:39 Sure. Well, your time is just about up. 3:41 And before I jump to JW, I just want to remind the resolution of the debate is technically 3:48 BIP300 slash 301 deserves at least as much attention as the Lighting Network. 3:53 A little bit of a hand of a resolution, but it's all we can kind of get to agree to 3:58 because there's a little bit of debate over semantics. 4:01 But I will now turn over the floor to JW, okay? 4:06 And you've got three minutes now. 4:09 Right on. So, yeah, I won't go into my background too much 4:13 because I really want to just focus on context. 4:17 But I'll say briefly that I wrote the Bitcoin threat model. 4:20 And you can check that out if you're interested. 4:27 So there's a few underlying concepts that I think are worth talking about. 4:30 One is that Bitcoin is really critical to human survival. 4:34 We're at this tipping point in history where technology like mass surveillance and censorship 4:39 is either going to completely or nearly completely eliminate individual freedom 4:43 or technology like the Internet and Bitcoin is going to empower the individual 4:47 like probably never before in human history. 4:49 But Bitcoin is fragile. 4:51 Or another way to say it is we don't know exactly how fragile it is. 4:55 We almost lost the 21 million cap. 4:58 I think that was a year ago when there was an inflation bug discovered. 5:01 Totally could have been exploited. 5:03 But we were lucky it got fixed and found and dealt with. 5:06 Before that, we almost lost our ability to sync the network with the SegWit2x attack. 5:13 We also don't know how many of the most influential and popular Bitcoiners 5:16 are actually trying to destroy Bitcoin. 5:18 If you look back at the history, we have guys like Gavin and Hearn and Ver. 5:23 And if they're any guide, then a significant portion of the people that are names now 5:29 that people respect and think are trying to secure Bitcoin are actually trying to destroy it. 5:34 I don't think it's worthwhile, really, even though occasionally I fall into this 5:38 trying to identify them. 5:39 But it is really important that we all have that attitude and that mindset 5:43 and realize the context in which we're operating. 5:48 Also, if we lose, we might not be able to get this back. 5:52 We might, you know, if Bitcoin's broken in some way, 5:55 we might be able to just agree on previous valid transactions, 5:59 do a checkpoint or something, make a fix and soldier on. 6:02 That's possible. We don't really know. 6:04 Or we might need to wait until the banksters and their intelligence agencies 6:09 forget that this is a possibility, right? 6:11 This could be a once-in-several-generation opportunity to build something like Bitcoin. 6:16 Because had Bitcoin been recognized for as important as it was when it was first invented, 6:22 there would have been a lot more resources dedicated to preventing it. 6:25 I think we all can say that with certainty, especially with the recent El Salvador news. 6:30 So, you know, we have to be careful, right? 6:33 The conclusion then is we have to be careful. 6:35 And to say the fate of humanity depends on us being careful, 6:39 it's not much of an exaggeration. 6:41 I mean, we don't really know, but it is a very important technology 6:45 at a very important point in history. 6:47 So with that said, what's interesting is Paul is not going to argue that Drivechains are ready, right? 6:54 That's what I wanted the debate to be. 6:56 Yea or nay, Drivechains are ready to go. 7:00 And he won't debate that because he doesn't think that they're ready. 7:03 So what are we even debating here? 7:05 We had to come up with this goofy phrase. 7:07 Ultimately, I think we're going to be debating, is Bitcoin Core ready to go? 7:10 Okay, your time is up. 7:13 All right, Paul, over to you. 7:16 Three minutes. 7:20 Paul, go ahead. 7:22 Okay, I didn't realize I had to manually unmute. 7:24 Okay, thanks. 7:25 So none of that had anything to do with BIP300 at all. 7:30 So that puts me in a kind of interesting position of having three minutes to sort of kill. 7:35 I guess he did say that it's not ready yet. 7:41 I don't know. 7:42 Like, it's 99% ready. 7:44 So it's true that it's not completely ready yet. 7:48 We're still tweaking it. 7:49 I've intentionally delayed finishing it for a couple of reasons. 7:55 One is that altcoin developers have told me that they will copy Drivechains into their projects when it's finished. 8:01 So I kind of have a dread of actually saying it is finished. 8:08 Also, once it's coded, we actually can't stop miners from activating it unilaterally. 8:16 So if you hate Drivechain, you should thank me for delaying it. 8:21 But it really is 99% finished. 8:24 As I said, we have already the working Zcash sidechain example. 8:29 And you can see the video on the front page of drivechain.info. 8:36 It's mostly finished, but it is definitely not ready to be merged, per se, because you would want... 8:42 I completely agree that you would want to have a lot of testing and all kinds of stuff that's not testing the idea, 8:51 but testing just like every line of code, that type of thing. 8:56 I don't particularly understand the complaint. 8:59 I remember that, for example, with SegWit, Peter Weil presented that on Scaling 2, the morning of the second day. 9:11 That was December 2015. 9:13 And then the code, you know, it wasn't ready, so to speak, until after Scaling 3, which was October 2016. 9:23 I'm not really sure that BIP300 is in, like, a totally different category on the basis of how ready it is. 9:32 The presentation that Peter Weil gave was for the express purpose of shifting developer and user attention towards the SegWit idea. 9:41 So that's, like, what I'm doing now. 9:44 But there would be no reason to say, like, it's ready to be merged tomorrow. 9:47 I've always been very clear that it is not that. 9:52 And it is unfortunate. 9:53 I think some supporters do get a little overzealous, and they say, you know, merge it tomorrow. 9:58 And I have tried to make it clear that it is not ready to be merged tomorrow, but it does deserve more attention. 10:05 It deserves to be thought about, you know, something more like the Lightning Network. 10:11 And so that's, I don't know, like, they literally just sent me one or two messages about what the topic would be. 10:23 But I do agree that it's not ready to be merged immediately. 10:27 All right. 10:29 Paul, your time's up, and we'll go back to JW. 10:31 Thanks. 10:32 Go ahead, JW. 10:34 Yeah, so what I wanted to debate was if the design is ready. 10:38 Not whether the implementation code and all of that is ready, right? 10:42 Because there are, I mean, ultimately, if the design is not ready, then the design doesn't exist, right? 10:47 When you're talking about, like, design architectural level incentives, are things going to break? 10:54 What you mean by it's ready, right? 10:57 What we mean by, like, Drivechains or BIP300 or 301 is not the actual implementation code, of course. 11:03 What we mean is the idea, right, is Drivechains as an idea, as a design, as it's described, solid. 11:10 And so ready means that other people, you know, sidechain architects have looked at it, you know, all the people that Paul's mentioned so far, 11:20 all the people that we respect have looked at it and said, yeah, the design is solid. 11:24 Then it goes on to the implementation phase where people try to actually write codes to implement the design. 11:30 So what I wanted to debate is, are Drivechains ready? 11:33 Is BIP300, 301 ready? 11:35 Is it good? 11:36 Is it solid? 11:37 Is it trustworthy? 11:38 And Paul doesn't want to debate that because it's not. 11:41 It's not ready. 11:42 It's not solid. 11:43 And we're going to go into the details of it, but I do think it's worth making sure that we're on the same page here. 11:49 Because if it's not ready, we don't know if it will work. 11:53 In other words, it could cause damage. 11:57 Paul has argued many times that there's no chance that this could cause any damage to the Bitcoin main chain, right? 12:03 That all of the risk, if something blows up, is on the sidechain. 12:07 Well, if that was the case, then you could argue that it's ready because then there's no risk, right? 12:11 There's no risk to Bitcoin. 12:12 Why wouldn't it be ready? 12:13 If it gives us any functionality, no matter how stupid, if it's completely risk-free, why wouldn't we implement it? 12:21 And if you listen to Paul talk about what it gives us, it gives us everything. 12:24 It gives us utopia, right? 12:26 We can have big blocks safely. 12:27 We can have Ethereum smart contracts safely. 12:30 We can do everything safely and completely obliterate the altcoin narrative. 12:35 So if it's ready and we get all of that, if the design is not flawed, in other words, we're confident that the design is safe, then we should absolutely implement it. 12:46 But Paul doesn't want to argue that the design is safe. 12:49 He doesn't want to argue that those BIPs are actually solid. 12:53 It's not getting the attention it deserves, right? 12:55 So the important point there is that he's intentionally moving us away from, is this a good design that will or will not break Bitcoin and gives us something, to are the Bitcoin core developers mean to him or cruel or whatever? 13:09 So we've moved from technology to politics. 13:12 If we're not debating whether the design is solid and we're debating whether it's given enough attention, the implication there, if you peel that back, is, well, why wouldn't it be given enough attention if it's good? 13:22 And the only answer and the answer that Paul has suggested many times over the years is that the Bitcoin core developers are meanies in one sense or another. 13:31 So ultimately, this comes down to whether you think that. 13:35 Go ahead. 13:36 You can face your thought. 13:37 I was just going to say, ultimately, it comes down to whether you think that it's being unfairly ignored. 13:42 OK. All right, Paul. 13:46 OK, great. 13:47 So I think this is a lot of meta talk. 13:51 I am absolutely. First of all, I presume when someone says this bit is some bit ready, they mean, you know, it's the code ready to be a pull request opened or something. 14:02 So if all we're talking about is design, then I'm happy to talk about the design being ready. 14:07 The design actually has changed very little from the original November 2015 post to today. 14:14 It's changed almost not at all. 14:16 So the design is very stable and I'm happy to talk about about the design as for shifting the conversation from technology to politics. 14:24 I mean, we're I presumed I thought we were going to come here today to talk about technology. 14:30 So I'm happy to talk about that in any capacity. 14:34 You know, we have yet to hear any actual objection to the technology. 14:41 Actually, it's very ironic that what J.W.W. is saying is it only really applies to him. 14:49 He's the one who is trying to shift things around to make it sort of interpersonal or whatever. 14:54 Whereas I'm happy to talk about anything related to the design or the implementation of the design or the goals or whatever. 15:03 So I'm happy to say that that I'm happy to argue and claim that the design behind the 300 is ready. 15:11 It's been ready for people to talk about it ever since I published it in November 2015. 15:16 So as for there being, you know, it's designed so that it is designed so that there is no to to make sure that problems on the sidechain do not affect the main chain. 15:30 So that is the that is the design goal. And that is the purpose. 15:35 So that is, you know, that it's true that that's what I claim. 15:42 It's also true that I think it if if it's such a great idea, why wouldn't we be working on it? 15:48 Well, that's what I've been saying. So I agree with that. And does it promise us everything? 15:54 Well, I think it promises us quite a bit. It does have a great deal with. 15:59 Altcoin competitiveness, privacy, scalability, interoperability, new features for Bitcoin, good narrative, presenting a good argument to the world as to why they should pick Bitcoin over the banking system. 16:16 So I do believe all that. If J.W.W. actually has anything to say about BIP300, I think he should say it. 16:24 It's not only that I've said that Bitcoin core developers are meanies. 16:29 I have said that many of them get paid enormous salaries and have basically no one no oversight on what they do. 16:35 They enjoy that state of affairs. I also published an article called. 16:41 I think it was called Why Drivechain is Harder to Understand than Previous Soft Forks. 16:46 And that I enumerated reasons why. So that's not these are my only my only basis for complaint. 16:54 Although I have made that complaint from time to time. 16:56 All right, great. J.W., the floor is yours. Three minutes. 16:59 Yeah, so. I am setting up the context here because there's not that much to talk about on the technology side. 17:06 If you understand the open source development process and you believe that the Bitcoin core developers and, you know, this is not a specific group. 17:13 Right. Anybody can become a Bitcoin core developer that has something to contribute. 17:18 So there's no there's no gatekeepers here. So if you understand the open source software development process, you don't you don't get frustrated that something doesn't get implemented. 17:27 Right. And you don't you don't like Paul has done for years in very subtle ways disparage that that group. 17:34 Right. And he just did that. He just said, you know, I have said over the time. 17:38 Oh, yeah, I do not understand why it's not getting attention. And the reason that he's doing that is to create that question in your mind. 17:44 Right. This is ultimately a campaign against the Bitcoin core developers to convince you that they're not giving it the attention it deserves. 17:52 And this is not like, hey, I'm putting up a Twitter post. I'd like you guys to look at it. Let's have a conversation. 17:57 This is an ongoing multi-year effort where he's constantly coming back and saying it's not getting the attention that it deserves to create that that doubt in people's mind. 18:06 And that's where ultimately you end up with, you know, crazy conspiracy theories around Blockstream and lizard people and all that sort of stuff. 18:13 So it is important to have that context. But now we can go into the technology and talk about why why I don't think it's a good idea. 18:21 And I'm theorizing here. Right. All I'm doing is saying this is why I think it's not getting the attention that Paul would like it to get, because I think it's a bad idea. 18:29 The fact that it's not getting attention is a much better case. If you understand the open source development process, that it's a bad idea because I'm just one dude. 18:37 And as a lot of people have pointed out, I'm by far not the smartest or the most capable person to talk about this topic. 18:45 The reason that I'm here is not, you know, for any other reason than I was trying to explain to bake why I think it's a bad idea. And he said, hey, why don't we have a debate? 18:52 So let's talk about why it's a bad idea with the context that when we have to be super careful and to this is really, really important for humanity. 19:02 So so here's here's some reasons that it's a bad idea. Drivechains rely on completely new incentives. 19:09 No matter what Paul tells you about how it's there's no chance that this could affect the main chain. 19:15 You have to be an idiot to think there's no chance that this can affect the main chain. It gives us all of the things that he claims it gives us. 19:21 And we have no interest as a community. Right. The open source developers have no interest in it or not very much interest in it, let's say. 19:29 Otherwise, I wouldn't be the one debating it. Right. So miners can steal Bitcoin. 19:36 That's what that's all you need to know. With this design, miners can steal Bitcoin. 19:40 With this design right now or where we're at right now, miners can reorder transactions. 19:45 That sucks if we could fix it. We would. But it's the best that we've come up with. 19:49 That's bad enough with this design. Miners can steal Bitcoin. 19:57 All right, Paul, good to go. Sure. 20:02 So the whole angle of miners being able to steal from sidechains, it's just a misunderstanding of the design. 20:11 It's really really what it is, is it's it's a question of ethics. 20:16 If if SPV proofs are used like in sidechain design, then the sidechains are vulnerable to theft by miners. 20:26 And that was true in the Blockstream paper. And that's true in Drivechain. 20:29 And that's true for any SPV proof. But that only affects the people who have chosen to opt in. 20:35 Which, you know, at the time, especially in November 2015, when I wrote that, there were many large blockers who said that they they would only use SPV mode. 20:44 And they they were totally 100 percent happy with that security model, actually. 20:49 So but but instead, if you use something like a mandatory extension block, then it becomes part of the protocol. 20:57 And BTC now basically becomes like Bitcoin SV or something. 21:01 So so that affects everyone, even the innocent people who may have wanted nothing to do with all the old rules. 21:10 And it gets even worse than that, because technically it's like a developer tyranny because you always have to run the latest version. 21:16 So and then that's only if you want to have some kind of interoperability at all. 21:22 If you don't, then you live in the altcoin world where you have altcoins, hard forks, you have disagreements about activation. 21:30 And so people are still affected because some altcoin or hard fork could try to displace Bitcoin and then and then everyone would be very affected if they succeeded. 21:42 So this is the entire design of BIP300 is for the express purpose of. 21:50 Protecting the main chain from people's ideas about what to do with the blockchain technology. 22:00 Let me see, I think I tried to write down what you were saying. Let me see. 22:03 OK, so first of all, if it's true that if you think that the Bitcoin core developer team is infallible, then you can just outsource all of your thinking to them and then you never need to think for yourself. 22:15 And and, you know, some people enjoy that kind of thing. 22:20 Others say that. The whole reason that a community is strong and produces the best ideas is because each of its members thinks independently and challenges the others. 22:37 As for relying on completely new incentives, again, it's a question of ethics. 22:43 You want who you want to be affected, the people who opt in or the people who are innocent bystanders. 22:49 So that that's the whole point of the miners can steal a thing. 22:53 Again, it could be trivially altered to be a mandatory extension block. 22:57 It's not as though that is some kind of. 23:00 Flaw, in fact, it is the entire. 23:04 Is the entire goal to protect the other people on the main chain from the sidechains. 23:09 Activity. 23:11 All right, JW. 23:13 Yeah, so a couple of things, because the real debate here is around how we interact with core. 23:18 I'll address that first. So it's totally fine. 23:21 And obviously part of the open source project to suggest ideas and even to say that ideas should get more attention. 23:28 But that's not really what Paul does. 23:30 What Paul does is he implies that it's not getting the attention that it deserves, which, of course, opens the door for people to say, why isn't it getting the attention it deserves? 23:39 It's got to be because people are either incompetent or malicious. 23:42 If you understand that anybody can suggest an idea and anybody can work on any idea. 23:48 And and what you're saying is that this idea has grossly been underappreciated and the attention that it deserves has been stolen from this idea. 23:59 The only possible solution is either people are incompetent, right? 24:04 They're just not smart enough to see what a great idea this is. 24:07 And, you know, Paul has just been extremely patient with everybody or they're doing it on purpose. 24:15 The third option, which I think is what you can see if you just look into it, you know, for an hour, is that it's very risky. 24:21 Right. He's saying that people, you know, no, they can't. Miners can't steal. 24:25 If you after this debate, you just look up the conversations that Paul has had with anybody. 24:30 This is the criticism. Right. Send send Ruben Thompson a DM and just say, hey, can miners steal Bitcoin? 24:37 And he'll confirm to you that absolutely. That's why people are not excited about it, because miners can steal Bitcoin. 24:44 Now, Paul will say they can only steal Bitcoin slowly or yes, they can steal Bitcoin. 24:49 But the incentives of wanting to damage the network are so great. 24:53 They won't want to steal Bitcoin. But that's not the point. Right. I'm not saying they can steal it fast. I'm saying that they can steal Bitcoin. And that's enough for you to know, whoa, this is not completely risk free. Right. It might work. I'm not even I don't even have to argue that it doesn't work or that it wouldn't be great. All you have to know is that if we break Bitcoin, we may not have another chance. So we have to be very careful. And miners can steal Bitcoin. And if you put those two things together, it's not going to work. 25:20 But if you put those two things together in your head, you can see that probably the reason this isn't getting enough attention is not that these guys are meanies, but that they're competent and there's better ideas to work on. 25:32 And as far as, oh, it doesn't affect Bitcoiners. Look, if Bitcoiners and we have this sidechain and they put funds into it, these are the Bitcoiners that are going to be affected. Right. 25:43 Bitcoiners. These are not like off-tard idiots that are putting money in here or losing. These are people, you know, the same people that we're constantly trying to protect from losing their funds on exchanges. 25:53 Those are the people that are going to be hurt by this this flawed sidechain ideal idea. If miners do as I expect and they steal the Bitcoin, that slows adoption, especially if it's unclear in the general public's mind whether actual Bitcoin was stolen or not. 26:10 And I think that that will be extremely unclear if these sidechains get popular. So it will damage Bitcoin adoption. It will take Bitcoiners off the map. 26:20 All right, Paul. 26:51 in 2015, 2016, to even keep track of what everyone was doing. And the, you know, now it's like some more complicated than ever. So an enormous number of people are working on an enormous number of things. And they're mostly interested in what they're interested in. 27:12 And I, you know, it's very difficult for me to keep up completely with everything that everyone else is doing. So that's really what I think is going on. I do think there are some some quirks. Once, well, maybe I shouldn't say those things, but I will say another thing that I do think is irrelevant is this idea of responsibility. 27:31 It's kind of like there's a there's a misincentive at the FDA, where if they approve a drug that saves millions of lives, but like five or six people are misdiagnosed, or they have an allergic reaction to the substance or whatever, then, then the FDA will be blamed, but they won't be blamed for the you never see the million lives that die when the cure was, you know, was being held up by the FDA. 27:55 I do think something similar is going on where, with the idea of the theft, where the developers of Bitcoin are, you know, Bitcoin Core, they don't want to kind of take responsibility for that, which I can completely understand. 28:14 I, my argument is that it's the sidechain developers, it's a transfer of responsibility from Bitcoin Core out into a different group who is then responsible. But it's like the free market doesn't guarantee, you know, that everything that you will escape bankruptcy, it's the entire threat of bankruptcy is what keeps businesses honest. 28:35 So that's something else I wanted to mention, though, is that a 51% hash rate can steal Bitcoin from the lightning network very easily with impunity, they just censor all the justice transactions. 28:48 So if the criterion, which is the agreed upon debate criterion, and the premise that JW introduced is that you should never pay any attention to something where miners can steal the coins, it's trivial in the lightning network for them to do that. 29:07 I just open channels with, I open a channel with Vake, and I open a channel with JWW. And then JWW pays Vake for BTC. And I broadcast the old state with Vake and the new state with JWW. And then normally, Vake would be able to stop that with justice transaction, but it was 51% hash rate, you can just censor it with impunity. 29:31 So you can steal from the lightning, 51% of miners can steal from the lightning network. So I don't argue that people should pay attention to lightning. 29:39 Okay, so again, Paul is still trying to make very subtle claims that there's a problem with the Bitcoin core development process, right? That that's really what's an issue here. Because if, look, if that wasn't an issue, then we would just say, Oh, well, it's being prioritized correctly. And we're all marching along. It's, you know, one big happy group, exploring interesting ideas and trying to find what works. 30:05 But you can't claim that something's not getting enough attention for multiple years, and that the process is working. So he's, he's trying to thread this very difficult needle, where it actually doesn't exist, right? So earlier, he said they enjoy a very lucrative income, right? It was one sentence in passing. But these are the keys that you have to look out for with Paul, because that's actually what he's trying to communicate. 30:27 He wants you to think that there's a problem with the process, and that the incentives are messed up. But at the same time, he'll say, well, I just think they don't know how to, they don't have enough time, right? They're, they're just kind of distracted. You can't say that a development team, whether it's open source, or even at a company, is completely ignoring the Holy Grail to go work on things that are not as important, and still say that they're competent, right? 30:52 Part of being a competent development team, part of being a competent, lucrative, open source community building good things, maybe the most important part of that is prioritizing what you work on. If you're, you know, polishing the hubcaps, when the engine is redlining, something's wrong, right? That's possibly the worst possible thing that could go wrong in a development process. 31:12 So he's going to do a good job of like planting seeds here and there like that. But also trying to not be so direct that that you guys realize what's going on. He also did this when he compared it to bad incentives, right? So we all know the FDA is a nightmare, and it kills people. And the reason that it does that is a combination of corruption and sort of disinterest, right? 31:34 So when you compare the Bitcoin core development team to the FDA, it has all of those connotations. So what you have to do with a guy like Paul is you have to stop, you have to like hit pause on this podcast, if you're listening to it, and go, okay, what are the implications of what he's saying? Because he'll never say anything directly. He'll always say it by inference. The core development process, it's open source, anybody can participate in it. 31:56 There is no like manager deciding there's no hierarchy, like at the FDA, if you want to implement this, and you think it's a good idea, and you have the right skill set, then you just implement it, right? And worst case scenario, you you know, you fork off from Bitcoin core and build your own implementation. All of this stuff is addressed in the process. There is no broken part of this. Otherwise, governments would be exploiting that like crazy. And we don't we don't see anything like that in open source projects in general, right? 32:25 If they're good, and they're healthy, they prioritize correctly. He's also trying to be really subtle here and saying that you can steal funds from a lightning transaction. If you have a 51% attack, here's here's the key thing that you have to understand. Miners can steal funds versus miners can mess with the order of transactions. That's a very different thing. 32:45 All right, Paul. 33:16 in order to steal from the lightning network. And I think the lightning network is perfectly secure. I'm not I'm not worried about miners stealing from the lightning network at all. I just bring that up because his criterion is supposedly that if that's ever the case, then you shouldn't pay attention to it. It's also true that merely having the ability to sensor messages from the blockchain is actually enough to just steal layer one Bitcoin transactions. 33:43 And I presented about that at building on Bitcoin in Lisbon, Portugal. And I was invited to come speak there by the Bitcoin core developers that supposedly have all this animosity with. So that's intriguing. One would also wonder how I ended up on the scaling committee, the program committee for scaling for if that were the case, or why I was invited to speak at Bitcoin 2021. But I don't want this to become like a reputation off. 34:11 This whole thing has become you have to notice that he hasn't actually said anything about VIP 300 or 301. Other than to point out that the miners can steal critique, which is not really a critique of VIP 300 at all, since it applies to every single sidechain scheme that is based on SPV proofs. 34:33 And as I tried to explain earlier, if you do not, if you do not want that to be the case, then you the only other two options are much worse. So I think the audience should challenge JWW to say something actually about VIP 300 or 301. 35:04 infallible, or whatever you want to say about that. The only way that people could know that is if each particular issue is addressed independently. So I will, you know, again, people should like, ask themselves, you know, how do I know that that development is working? 35:29 And the only way you could know is by actually examining the contents of each argument. And so, again, I don't know, this debate is not really about anything other than it's not really about VIP 300 at all. I don't, you know, so I don't really know what to say. 35:46 All right, JW, go ahead. 36:17 transactions. They can't actually steal funds. Your funds are secured by your private key. If you don't sign a transaction, you know, that balance is not going to move, right? It would be an invalid transaction. If you introduce this VIP, that's no longer necessary. Miners can actually steal Bitcoin balances. That's fundamentally different. Very easy to verify that that's the case. And that's the concern, right? 36:43 So we are definitely talking about it. We're not getting into the weeds of the VIP. We're not getting into all of you know, this Rube Goldberg system of incentives that supposedly make it so that miners will never do that. Because it's not necessary, because I don't actually have to prove that it's a good, good design, or it's a bad design. All I have to prove is that it's an, it's not obviously safe, right? 37:06 We wouldn't have activated taproot. We wouldn't have spent a ton of time over it over the years talking about it and digging into it. If basically the moment that it was published, everybody said, Yes, this is a safe design. And to contrast that with BIP300/301, many people have looked at it and said, This is not a safe design. Now, maybe it is, maybe they're wrong. But it's important to understand that that's why it's not getting attention that it deserves. 37:33 Yes, Paul knows the Bitcoin core developers. He's very cordial with them. You know, these guys are not. These guys are not like fighting with each other. But the core issue here is, are they giving this thing the attention that it deserves? Or are they unfairly ignoring it? So he still wants you to believe that they're not a pain. They're not paying attention to this, either from corruption or disinterest, right? 37:53 So he's not saying like, Oh, they are going to pay attention to it. I just haven't really promoted it much or whatever. He wants you to start thinking about where their income comes from, what their incentives are all these sort of things. Because he wants you to believe that it's not getting the attention that it deserves. Even the title of this debate is, it's not getting the attention that it deserves, because lightning is getting more attention or whatever, however, it was ended up being phrased. That was because he wants it to be about that, right? It's, it's underappreciated. And 38:23 it's, it's an indication that something is wrong here, right? So that's still the issue. And it just doesn't make sense. 38:32 We lost you JW. 38:34 Oh, good. I was wondering if it was me. 38:40 All right, well, JW's time is just about up unless I hear from him. I'll give him a few more seconds. 38:47 Okay, well, we kind of debated a lot about things around the actual BIP itself, the incentives of the core developers, the approval process for core, the merge process. I kind of want to hear a little more about the actual attacks on Bitcoin that are theoretically possible. I mean, I know JW talks a lot about, you know, the Bitcoin market, but I want to hear a little bit more about the actual attacks on Bitcoin. 39:12 that are theoretically possible. I mean, I know JW talks a lot about, you know, the miners can steal the money from the Drivechains. But what is the threat to the Bitcoin main chain to somebody who is completely, let's say, agnostic about this sidechain existing, just run the basic Bitcoin core full node? Maybe I'll start with JW. JW, can you hear me? 39:32 Can you hear me? Let me invite you back up again. So I want to see if JW could talk about what the threat to Bitcoin itself would be, and then Paul could respond to that. 39:49 Okay, well, JW, until you get back up on stage. 39:53 Paul, go ahead. 39:55 For him, I don't. So I don't know if he's connecting down. My assassins found his ISP. 40:02 Okay. Well, Paul, JW did bring up numerous times that miners could steal coins from a Drivechain. So maybe you could address like, does this have any impact on security of somebody who is not involved in that particular Drivechain? What are the potential attacks on Bitcoin itself, the main chain, from miners, I guess, stealing these coins or any other potential attack that you've heard raised against it? 40:32 Well, it's, I just like to point out that it's not as though like the miners just show up and take the coins in the very next block. And then, you know, 40:43 I got dropped there for a second. Don't mean to interrupt, but just wanted to let you know I'm back. And I don't, I don't know what I got cut off. 40:49 Let's just give Paul a few minutes to talk about, well, unless actually, I did want to hear you first, JW. You said that, so you brought up that miners can steal funds from a Drivechain. I want to hear a little more about what the attack on the Bitcoin main chain could conceivably be. So if you want to kind of discuss that for a few minutes, and then we'll throw it to Paul. Does that sound good? And then we'll do audience questions. 41:14 So just to be clear, when did I get cut off? 41:17 It was about the last 20 seconds you had of your last round. 41:21 Okay, great. All right. Yeah. 41:24 So what would be a threat to the Bitcoin main chain that you'd see possible? 41:28 So the issue is that miners can steal Bitcoin. And that's not obviously safe. 41:36 So I have written about why, how I think they could profit from doing this. But I don't even have to, I really don't have to go there to win in the sense that it's very obvious why this design hasn't been given more attention. 41:52 If you dig into it enough to understand that miners can steal balances, they never could do that before. 41:59 And so if it is a good idea, it has to be approached with incredible fear and trembling, incredible humility. And if it's not getting attention, it's a pretty obvious indication that a lot of folks don't think this is a good idea. 42:13 All right, Paul, so your response? 42:16 Sure. Well, I mean, again, this is a lot of meta talk. It's not actually about the idea. It's about what other people think of the idea. 42:25 But I would wonder if JWW is concerned at all for his own argument when, since it's become apparent over the last 12 months that this idea is rapidly getting more and more attention. 42:39 So now, isn't this circular reasoning now going to cut against his argument, I suppose? 42:48 I mean, this is if he's determined to avoid talking about any actual issue, and he only wants to talk about how much attention it's getting, which is meta talk that is not about the subject at hand. 43:02 But I just thought I'd throw that out there since this debate has veered so wildly into that off-topic direction. 43:12 Do you think that miners stealing balances from a Drivechain presents a threat to main chain Bitcoin holders? That's what I want to know. 43:19 No, I don't. I don't. And in fact, as I presented, many sidechain designs are such that they are actually bad for the entire ecosystem as a whole. 43:32 You have sidechain designs where people put up a weird contract that they get paid if some other chain reorganizes, or you have two different name identity chains. 43:43 That's no good. You have parasitic oracle chains. So there's many, many designs that are actually bad, and you need a way to get rid of them. 43:53 And so it's actually a good thing that there is something in place to hammer out a bad sidechain. 44:02 So I don't think that's the case at all. I mean, there's always the question of what affects the market price, but that's innumerable things affect demand. 44:09 So none of them is really specific to BIP300 versus the Blockstream skip list versus any other number of features that could be good or bad or experimental. 44:24 If anybody else wants to ask a question, feel free. 44:27 So can I respond to that real quick? 44:28 Yeah, go ahead. 44:29 I'm supposed to get the last word before we go to Q&A, right? 44:32 Yeah, absolutely. 44:33 Okay, so yeah, the fact that miners can steal Bitcoin, that's a significant change. 44:38 And that's really, again, all you need to know about the design for me to be able to win the debate. 44:44 Or at least for you to feel like the Bitcoin core developers are probably doing a good job, right? 44:49 The Bitcoin community is probably doing a good job prioritizing what they work on. 44:55 It is very much not obvious, let's say, that if miners steal significant Bitcoin from a Bitcoin sidechain, that that's not going to be damaging to Bitcoin. 45:08 Now, you could argue, I mean, as Paul just did, not a problem at all. 45:12 It could affect the market price, but the weather could affect the market price. 45:16 God only knows, right? 45:18 My point is, one, it's not clear that it's safe. 45:22 And two, it's not clear that it's safe. 45:25 That's all I can say, right? 45:27 If you give miners the ability to steal Bitcoin directly, where they didn't have that before, the only thing they could do is reorder transactions in a malicious way. 45:37 That's very, very different. 45:39 And there's very, very good reason to think that that's unsafe and that it would damage Bitcoin. 45:48 You still got a couple of minutes left, JW, if you want. 45:51 Okay, yeah. 45:52 I'll just say that, also, that is the BIP, man. 45:55 I mean, that is what we're talking about. 45:56 You keep saying we're not talking about the BIP. 45:58 Unfortunately, the BIP is so stupid that that is the BIP. 46:01 And that's the only objection that I've really heard, is that, hey, we're not really sure that it's a good idea to let miners have the ability to steal Bitcoin. 46:10 Maybe it's going to work out. 46:11 Maybe it's not. 46:13 As far as the details of the BIP, the fact that they can steal it, but they can only steal it slowly, and other mitigations, it's only worth going into those if you're really trying to say, okay, it's okay that miners can steal Bitcoin because they won't want to. 46:31 Maybe. 46:32 And I'm willing to concede that. 46:33 I'm willing to concede a maybe. 46:35 But as soon as you say maybe, that's not good enough to be the highest priority task for us as a community to work on. 46:46 All right, Geisler, do you want to ask a question? 46:49 Yeah, this question is for Jim. 46:52 What would you say if somebody said that miners can currently steal from Lightning by refusing to mine justice transactions, and therefore Lightning is no more safe than Drivechain would be? 47:06 Thank you. 47:08 I presume you meant JW. 47:09 So I'll let JW, a couple minutes, and then George Paul. 47:13 Okay, cool. 47:14 Yeah, so, I mean, what you're arguing there is that Lightning is insecure. 47:19 And you could argue that. 47:20 And I think it was smart for us to be very concerned about whether Lightning was going to be secure or not, and whether it was going to damage the network. 47:29 It's proven at this point. 47:31 It's rolled out. 47:32 It's working. 47:33 And so what Paul's trying to do is say, you can steal Bitcoin from Lightning, so if you can steal Bitcoin in this situation, it's also okay. 47:42 That's a very big logical leap, right? 47:45 That's not necessarily the case. 47:47 There's all kinds of reasons that it might not be as bad in Lightning, including the typical balance size that people have in Lightning, the cost of actually doing a reorg transaction to screw somebody over, the fact that you have to set up this double spend beforehand. 48:00 All of these things are mitigations that maybe make it safe in Lightning. 48:04 But you can't just say, oh, because you can steal from Lightning in some set of circumstances, it's fine that you can steal in Drivechains. 48:12 No, no, it's not fine. 48:15 It might be fine if there's all these other mitigations in place, but it's very much an open question. 48:24 Well, I mean, treating it as an empirical question, I think, again, it's just him disproving his own argument yet again, because he's not allowing the experiment to even be run. 48:36 I would perfectly be willing to say we should try this out, and then in the real world, we might discover that it never works. 48:44 I think that that's completely possible. 48:47 But that's not what the questioner asked. 48:50 The questioner asked, fundamentally, it is the exact same state of affairs where miners can steal from it, and yet we're all living with it today, and Armageddon hasn't fallen upon us all. 49:08 So he's trying to treat it like an empirical question, like, well, we don't know if the reality in the universe is that it's safe or not safe. 49:17 But if that's the case, then we should be allowed to run the experiment and find out. 49:23 We do want to have some kind of way of finding out. 49:26 The idea that there are a bunch of mitigations in LN and then the insinuation that there aren't in BIP300 is extremely bizarre, because with BIP300, the miners can only steal at all, in quotes, very slowly, over three to six months, a few times per year, with it being extremely obvious to everyone what they're doing, with it all declared in advance. 49:54 With it all declared in advance, there's an enormous amount of anti-spam, anti-DDoS stuff in BIP300 to make it as auditable as possible for anyone who wants to look into whether or not the theft is taking place. 50:09 It's extremely easy for people to react to the theft in a coordinated way, even without people talking to each other. So there are an enormous number of mitigations in BIP300. It is in the exact same fundamental category as lightning in that regard. And that was what the questioner asked. 50:34 All right. Time's up. 50:36 Yeah. All right. Ajax, you have a question. Ajax? 50:43 Hello. So this is more like a statement, not a question. So I was listening to your presentation, Paul, on YouTube, and you presented BIP300 as a way to avoid upgrading Bitcoin ever again. 51:02 So if there is an issue with miners being able to steal bitcoins, this is out of the question because a lot of people will not want to opt in to this. 51:14 And so you will have several chains where people will want to opt in. 51:21 And there is also questions that it's like if for if Bitcoin Core becomes responsible for maintaining security on those chains, too, they will have to upgrade the protocol in a way that does not break security of the sidechains, too. 51:43 And this makes the task much more difficult. And also, like, if there is any chance that Bitcoin can be stolen, BIP300 cannot become a path where Bitcoin Core will be upgraded in the future because this is not the way the protocol is supposed to work. 52:09 Let's let Paul take a couple of minutes and then JW can respond to that. 52:13 Well, I would think that Bitcoin Core developers would not take responsibility for anything other than Bitcoin Core. I think that's very healthy for people to only take responsibility for what they have control over. 52:23 What I was imagining in my head was you'd have the Bitcoin Core we have today, which is extremely functional and used by many people. 52:33 That's what we have now. And many people enjoy it a great deal. Obviously, we would still have that. 52:38 And then I was thinking we'd have like maybe two competing kind of like Bitcoin 2.0 chains or something, and they would be run by people who hate each other, be like wasabi versus samurai or something. 52:53 And then they would compete for adding new features. But I think most people just want to be able to send money from one place to another. 53:04 And so truly conservative users would just use the base chain and the base layer one chain, and they would not use either of the two Bitcoin 2.0 chains that are encumbered by the risks associated with the 300, which of course do exist. 53:24 But I do think that there is something to be said for the risk of updating the protocol. 53:32 With SegWit, we had a mandatory block size increase that suddenly somehow became popular among small blockers. 53:40 And that was something that was an upgrade to the protocol. And I don't know if we should keep doing that kind of thing forever. 53:51 I think that's its own risk. 53:55 Okay, D.W., you can go ahead. 53:58 Yeah, no, I think you're absolutely right. It's very obvious that it's not obvious this is safe. 54:05 And that's the bar that you would have to make for it to get prioritized for a lot of people to get excited about it and start working on it and volunteering their time. 54:14 There are not misaligned incentives here. We don't have lizard people on Blockstream controlling Bitcoin Core. 54:21 It works. The reason that people aren't working on this, if that's the complaint, which of course now it's not the complaint, now people are working on it. 54:29 But before it was, it's not getting as much attention as Lightning Network, and it should. 54:34 So it's kind of hard to pin Paul down on this stuff. 54:37 But as far as the mitigations go, yes, there is the ability to steal Bitcoin if you can reorder transactions in some very convoluted and narrow ways on Bitcoin right now. 54:50 It's a different set of mitigations in different convoluted, let's say, ways with Drivechains. 54:58 So the question is, are there enough mitigations in place? 55:00 Now, Paul hasn't even tried to say, yeah, miners can't steal for this reason or that reason, which you would think that he would. 55:08 Instead, he's just saying, hey, it's completely fine that they can steal because you can steal on Lightning Network. 55:14 It's kind of a ridiculous angle. 55:17 At the end of the day, though, what Paul is saying is they can steal. They can steal slowly. 55:22 They won't. And this also requires a change to Bitcoin Core, right? 55:26 We got SegWit. It was basically a security fix for transaction malleability. 55:31 And then other people were able to work on Lightning Network. 55:34 He wants us actually to change Bitcoin Core. 55:36 He wants us to change the Bitcoin network so that you can steal only slowly. 55:41 And his claim is that if you can only steal the Bitcoin slowly, you won't steal it because it will hurt the price. 55:48 But this is also a very narrow, weird spot because if you can trust miners not to steal, period, 55:54 if you can trust them not to steal quickly, let's say, then we don't need to make any change to Bitcoin. 55:59 And he can just roll that out. 56:01 So you have to believe that they will steal quickly, but they won't steal slowly. 56:05 Maybe that's true, but it's certainly not obvious. 56:08 All right. Joe, you want to ask a question? 56:11 Yeah, thanks. This is to both of them. 56:14 Is there any risk to someone's Bitcoin if we merge the BIPs and that person doesn't use the sidechain? 56:21 They don't want their coins at risk. 56:23 So are they affected at all if we merge the BIPs and nobody uses the sidechain? 56:28 To both speakers, please. Thanks. 56:30 Let's start with JW and then go to Paul. 56:34 Yeah, so Bitcoiners kind of understand that we're playing a bigger game than just trying to keep our own coins secure. 56:41 We need to increase Bitcoin adoption to win. 56:44 It's not just about number go up. 56:46 It's about human freedom, right? 56:47 We don't know how much time we have before the technologies that are being developed and released into the world are going to create a dystopia. 56:56 And so we need to as quickly as possible see things like El Salvador adopt Bitcoin. 57:01 So that's the issue. The issue is not whether your individual coins would be stolen. 57:05 If you don't use the sidechain, of course, that's the case. 57:08 But if people are confused and they believe that the sidechain is secure, which obviously there's a lot of people that do believe that. 57:16 There's a lot of plebs that believe it. 57:19 There's probably not a lot of Bitcoin core developers that believe it or Paul wouldn't have any complaints about their prioritization. 57:25 So the issue is, will we have people lose a bunch of money and it slows down Bitcoin adoption? 57:31 That's the concern. 57:32 All right, Paul, if you're done, J.W., then Paul, you have two minutes. 57:36 Yes, the question I asked, if BIP300/301 are merged and they never use any of the sidechains, can they ever be affected? 57:45 And the answer is no, they cannot be affected at all. 57:49 In fact, the way BIP300/301 are designed is that they have an even lighter touch than SegWit in that you don't even have to run a transaction. 58:00 You can run a version that doesn't even have the BIPs merged and it will still sync to the network. 58:08 And the only thing you'll notice is that very mysteriously, a lot of coins are accumulating in a few UTXOs. 58:17 Those are the UTXOs that have the sidechain balance. 58:21 And you'll be very confused by that, but you won't be able to spend it. 58:24 If you tried to spend coins from there, you would find that you were somehow not able to. 58:28 But you don't even have to run the software code, actually. 58:33 And that is because the whole thing is based on this ethical principle of people opting into things. 58:39 I agree with J.W. that there's a lot of indirect things, but the whole point of BIP300 is to massively improve those things. 58:52 Bitcoin adoption, privacy, scalability, new features, all of that is the entire purpose of having BIP300 is so that those new features are available to users if they want to opt in. 59:08 As for plebs being confused, I don't know if anyone here has the power to solve that any time soon. 59:17 All right, if you're done, then let's ask Ruben, go ahead. 59:22 And also, Ruben, I'll just leave you on stage since you're sort of knowledgeable about sidechains. 59:27 Go ahead. 59:29 Ruben should have really done this, man. 59:31 You know this a lot better than I do. 59:33 Well, yeah, I'm still on the fence in terms of how secure Drivechains is or isn't. 59:39 I really just have one question, mainly for Paul. 59:41 I was curious if Paul could kind of explain what he thinks the difference is between having these Drivechains be purely minor activated and having it be a soft fork. 59:55 So the difference, obviously, is that you don't get the slow payouts, right? 59:59 And that's something J.W. already said. 1:00:01 But I'm curious, kind of, Paul, what your take is in terms of how that changes the security. 1:00:06 Go ahead, Paul. 1:00:08 Two minutes and then we'll go to J.W. 1:00:09 Sure. Well, it changes the security drastically, I mean. 1:00:12 You would just need – you would want it to be a soft fork because what the nodes – when your full nodes do not enforce any of the sidechain rules and you do not need any sidechain blocks at all. 1:00:25 But what your full node does enforce if you activate BIP300 is it does enforce the BIP300 rules. 1:00:33 And that's all the so-called mitigations is the word we've been using today. 1:00:37 All the things that – namely, that the withdrawals have to traverse this gauntlet that's three to six months long and that there's a lot of potential to refute an erroneous transaction that sneaks in there. 1:00:50 And so if you did not activate it by a soft fork protocol change and instead you just had miners activate it, then, of course, we could all be using it tomorrow. 1:01:00 But then the coins – the miners could withdraw the coins in the very next block like at 3 a.m. when no one is paying attention. 1:01:09 And it's unclear exactly how well that would work. 1:01:15 Although, namely, that particular problem of the emergency sudden surprise attack withdrawal, that was one of the things that I didn't like about Blockstream's 2014 paper that I changed around and I think improved in Drivechain. 1:01:31 But I don't think that's really a good idea. I think it should be a soft fork. 1:01:36 All right, JW, go ahead. 1:01:39 Yeah, so just to recap, what we're talking about here is that Paul can do everything that he wants to do without having to get Bitcoin to change in any way, except that would allow miners to steal the sidechain funds quickly. 1:01:56 With the change that he wants to make, you would still be able as miners to steal the Bitcoin, but you'd have to do it slowly. 1:02:02 So you can think of it as like a really long time lock, essentially. 1:02:06 And so he'll say, oh, there's all kinds of reasons that that is secure. 1:02:12 It's not. It's not secure. At least it's not obvious that it's secure. 1:02:17 It's very, very possible that it could be very damaging. 1:02:22 So Paul wants to say there are all of these benefits to adoption. 1:02:27 It's going to be great for everybody, number go up, all that sort of stuff. 1:02:30 Drivechains are going to accelerate adoption. 1:02:34 But he doesn't want to acknowledge that there are downsides. 1:02:37 He wants to say, hey, there's no risk to the main chain. There's only possible benefits. 1:02:41 But obviously, there are a lot of possible negatives here, including number go up, go down, and adoption slow down. 1:02:51 If Drivechains do what Paul says that they will do, we should expect a significant number of Bitcoin, right? 1:02:58 A significant percentage to move into those sidechains. 1:03:01 And if those are actually insecure and miners wait until there's a nice big fat pot there to steal the funds from, 1:03:09 that's going to be very bad for all of the Bitcoiners and for the rest of the world that even has an adopted sound money yet. 1:03:15 So you can't say that there's no risk, only upside. 1:03:18 There's definitely a risk here. 1:03:19 And you also can't say that it's obvious that if miners will steal funds quickly, they won't steal funds slowly. 1:03:27 And that's the whole premise of BIP300/301 and Drivechains in general. 1:03:33 All right, Mario, you're floor. 1:03:36 Go ahead. 1:03:39 Yeah, so this question is a little not really central to the question of the debate. 1:03:43 But one comment I noticed, I think it was a couple of weeks ago, Jonas Nick had pointed out that he thinks that Drivechains as a type of hashrate escrow might not be the best we can do. 1:03:57 I'm wondering if anyone is aware of any research on other types of hashrate escrows that might be possible improvements upon Drivechain. 1:04:05 Let's start with Paul and then go to JW. Paul, two minutes. 1:04:09 Well, I mean, a very old idea is to buttress the hashrate escrow or the extension block or whatever you want to call it with some kind of zk-SNARK. 1:04:23 That's one that has been thrown around. 1:04:27 But I have always resisted this idea because the zk-SNARK is a sort of paradox where the only way to check that it is working is to not use it. 1:04:37 Which is to say you have to have all the messages and you have to check that they all follow all the rules in order to compute the zk-SNARK to make sure that the whole zk-SNARK system is working as intended. 1:04:48 And so, therefore, the zk-SNARK scheme isn't really that different from just regular SPV mode where, again, it's this thing where you sort of think that it is working until the only way to know that it is working is to check everything. 1:05:03 So it's not that different. 1:05:06 That was the big one. I don't know what Jonas Nick had in mind when he said that. Maybe someone can find out. I don't know. 1:05:19 Yeah, so there are actually quite a few ideas to improve on that. 1:05:25 As Paul mentioned, this idea is basically, as I understand it, the fundamental idea behind sidechains in general. 1:05:35 And Blockstream had this idea to do this sort of concept a long time ago. 1:05:40 And they pivoted because they realized, and Matt Corallo, there is a podcast from way back when Matt Corallo goes into this. 1:05:48 He's the one that came up with this idea of this kind of hashrate escrow concept or whatever. 1:05:54 And they decided that it wasn't a good idea, that it was too risky from a security perspective. 1:05:59 They thought that it would blow up and it wouldn't work. 1:06:01 And that's why they moved to a federated model. 1:06:04 A federated model is basically exactly the same, except you also have this additional layer of security where the members of the federation are also securing the coins in addition to the hash rate. 1:06:17 Because ultimately, you could just roll this out in a time lock and people could steal the funds and you wouldn't care about it. 1:06:25 But Liquid, the people that designed it were like, no, this is not a great idea. 1:06:30 Let's make sure that we have these federation members and they're responsible for securing it. 1:06:37 One of the really goofy things about this is that the mitigation is like, okay, well, if somebody steals the funds slowly, the ultimate mitigation is that we can do a fork. 1:06:49 We can just censor that transaction. 1:06:51 But that's the definition of a consensus failure. 1:06:53 And that's exactly what Bitcoin was designed to prevent. 1:06:56 So that's not a fix. 1:06:58 That's not a solution. 1:07:00 That's not a solution of a nuclear explosion. 1:07:04 You don't mitigate a nuclear explosion by getting out a firehose. 1:07:08 You try to prevent that from happening in the first place. 1:07:11 Maybe you can add something here. 1:07:14 Jonas, Nick, I think his post was more about the BIPs themselves and kind of how they changed Bitcoin. 1:07:22 And I think he was thinking more along the lines of, isn't there a simpler way to implement the same thing? 1:07:26 So it wasn't directly, I think, whether or not we should do something like Drivechain, but more like, how do we want to do it if we were to do it? 1:07:34 And also related to that, this is something that JW, you're probably not going to like. 1:07:40 But I sort of kind of looked into how you could potentially do something like a slow peg out with confidence. 1:07:46 And it looks like depending on what type of confidence we will get into Bitcoin at some future date, it looks like you can sort of do the slow peg out. 1:07:56 With a confidence structure as well, which sort of means that either we have to reject advanced confidence from Bitcoin in order to reject Drivechains, if you were against it. 1:08:06 Or we're going to get something like Drivechains when that time comes, regardless of whether BIP300/301 make it into Bitcoin. 1:08:15 Can I respond to that real quick? I'll be fast. 1:08:18 Or actually, can I have two minutes and then Paul goes for two minutes? 1:08:21 Yeah, go ahead. 1:08:22 Okay. Yeah, so a couple of things about that. 1:08:25 One is that I also wanted to mention space chains and soft chains, because those are Ruben's concepts. 1:08:31 And I think those are improvements on Drivechain as well. 1:08:35 So there is definitely, and actually, I think, correct me if I'm wrong, Ruben, you know, my time is up here. 1:08:43 But I believe that you can do everything that Paul wants to do with space chains. 1:08:47 The only difference is you have a proof of burn system. 1:08:49 So if you want to run a bunch of altcoin, you know, stupid experiments and blow stuff up, you can do that. 1:08:55 But it's going to be very, very clear it's not Bitcoin because you can't move it back. 1:08:59 As far as trying to prevent Drivechains, if you can implement Drivechains without making any changes to Bitcoin Core, that's analogous to being able to create a custodial solution. 1:09:14 I'm not that worried that something like Binance or Binance Chain or even Coinbase is going to say, hey, we have all these features and you can move your Bitcoin into it. 1:09:24 Ultimately, my concern is that people will think that they have Bitcoin. 1:09:29 And this has been a criticism of like Liquid. 1:09:32 And I think it's a valid criticism and it needs to be emphasized again and again. 1:09:36 But it gets a lot more difficult, I think, with Drivechains, especially if Bitcoin Core implements a change to enable them. 1:09:43 It's going to be presented as an upgrade to Bitcoin and people are going to run around like idiots, you know, and put funds in here and it's going to blow up. 1:09:51 And it's not going to be as easy to explain as when a custodial solution goes under. 1:09:56 So if it's done, that's, you know, that is what it is. 1:09:59 And I think as a community, we'll just have to do a good job of explaining that you're not on Bitcoin anymore. 1:10:04 Ruben, if you want to jump in. 1:10:07 Yeah, just to react to that, like I don't think like space chains do kind of a subset of what Drivechains do. 1:10:15 If Drivechains work as Paul thinks it does, then basically that would make space chains pretty much pointless. 1:10:24 Maybe there are some niche use cases there. 1:10:26 But I would say Drivechains are kind of superior in terms of what it could potentially do if it actually works as Paul hopes it does. 1:10:34 So I don't think it's quite like, you know, the replacement, but I guess you could make the argument that at least it makes Drivechains slightly less. 1:10:44 Like at least some of the things we can do with Drivechains, we could do with space chains. 1:10:49 But I don't think it's a straight up replacement. 1:10:51 Sure. 1:10:54 Yeah, I mean, you get a chain that basically doesn't really have this kind of Bitcoin store of value token. 1:11:01 So if you have with a Drivechain, you can literally move your Bitcoins to another chain and then you can use those Bitcoins in any type of smart contract that you want. 1:11:11 But that's just simply not possible with space chains. 1:11:14 And space chains sort of work around that design limitation and kind of look at what is possible despite that limitation. 1:11:21 But, you know, Drivechains, in that sense, just have a clear leg up. 1:11:25 Paul, you want to go ahead? 1:11:27 Yes. Anyone who, well, I'd like to thank Ruben for setting the record straight. 1:11:34 And it's fortunate that he did, because what I'm now going to say is that anyone who could possibly think that space chains could do everything that Drivechain could do has basically zero technical understanding of what's going on at all. 1:11:49 I said with the exception that you can't move the coins back. 1:11:52 Yeah, well. 1:11:53 So that's exactly what he clarified. So he didn't clarify anything that I didn't already say. 1:11:59 Right. So you can't do anything with Zcash like coin mixing. You can't do any betting. You can't do any kind of scalability, transaction throughput. 1:12:10 So anyone who would even suggest that doesn't really know what they're talking about at all. 1:12:15 And so that's the answer to that. I don't know. It's interesting that then JWW critiqued custodial solutions and said he wasn't worried about them at all. 1:12:27 But then earlier he was saying that how great the liquid network is, although he did then say that it was a critique of liquid to point out that it is custodial Bitcoin. 1:12:40 But I don't know. That all seems very poorly thought out to me. 1:12:45 Space chains are basically preemptively destroying all the coins. So you don't have to worry about miners stealing them, but you also can't get them back. 1:12:51 So if you have a checking account and you think it's better to just destroy the checking account or exchange it all for Chuck E. Cheese tokens or something, 1:13:02 then to run the risk that possibly something might happen to it later and you may lose it all, then yes, space chains are better. 1:13:14 Space chains are good if you want to do something like a name system or an asset system where there's no need to actually have any money come out of it ever. 1:13:26 Okay. Does anyone from the audience have a question? 1:13:31 Can I respond to that? 1:13:33 Sure, go ahead. 1:13:35 Okay, so again, I said that you can't move the coins back. So he's just trying to obfuscate the whole conversation. 1:13:42 What I said is the functionality. So you can do, from what I understand, and again, Ruben's the expert, you can do all kinds of stuff. 1:13:49 And if you can't do it with space chains, this whole proof of burn concept has been around for a long time. 1:13:54 And there's no reason that you couldn't take some Bitcoin, provably lock it up, and then do whatever you want on a completely separate blockchain that's using the fact that there was provably destroyed Bitcoin to do that. 1:14:06 So that's the point. And it's true. And so whatever functionality or features that you want, you can get, you just can't get them in and then back out. 1:14:18 As far as me being okay with custodial or whatever, I'm okay with whatever anybody wants to do. 1:14:24 But if somebody does something that's likely to deceive a lot of people and slow the adoption of Bitcoin, I'm not a fan of it. 1:14:30 I'm not a fan of the fact that Coinbase doesn't do proof of reserves. I can't stop them from doing that. 1:14:37 So what do we do instead? We do the best that we can to educate. 1:14:40 So if Drivechains gets activated in some way or gets deployed in spite of the fact that the VIPs don't result in any change to the Bitcoin core, then I will do the same thing that I do with custodial Bitcoin. 1:14:52 And the same thing I do with liquid Bitcoin. I'll say, hey, there's pros and cons, but you got to be sure that you understand that you don't have anything close to the security assurance that you have with Bitcoin mainchain. 1:15:03 And as a community, we're just going to have to do a really good job doing that to prevent that. 1:15:07 We're just going to have to do a really good job doing that to prevent somebody from thinking they have Bitcoin and having it all stolen, because that's not good for any of us. 1:15:34 If you have the right to swap your Bitcoin for some altcoin like Ethereum, if you have the right to send your Bitcoin to an unspendable address and destroy the Bitcoin, then you as the user and the consumer, you should have the right to send it to a weird script. 1:15:52 And that is all that BIP300 is at the end of the day. And that is why Ruben correctly brought up that it may be possible for people to eventually just send the coins to a script that is so complicated, it just replicates all BIP300, but in a way that is not subject to any kind of the peer review or import or regulations that I've put BIP300 through. 1:16:17 But I would like to hear more from the audience. 1:16:20 Okay, go ahead, Ben the car man. 1:16:22 I have a question mostly for Paul. I'm just curious. I think BIP300 301 could potentially be interesting, but it's just a lot of extra work to do. 1:16:34 And there's already tons of proposals that I think will be a lot more useful today, like things like Sikash Zenit Preval or OP_CTV or even stuff like Graftroot, which we know has material, new use cases and things that can add to Lightning or make everything a CoinJoin or stuff like Covenants. 1:16:56 Versus Drivechain, it adds us the ability to add new sidechains more easily and different security models. But no one's like, oh man, I would totally build a sidechain. At least as far as I know, no one's like, I want to build a sidechain, but I only will do it with BIP300 sidechains. 1:17:16 That's my biggest qualm with it. It's a cool idea, but there's not things that people are ready to build that are just waiting on this to come out. 1:17:26 I actually have a different project. The original Oracle project called Truthcoin is such a thing that you suggest. And then the entire reason I created BIP300 at all or advocate for it at all is because I was interested in doing that project. So you can go to bitcoinhivemind.com if you would like to learn anything about that project. 1:17:54 I've also published about other projects that I think would be cool. One that Satoshi Nakamoto thought was cool was Namecoin. And that would lead to uncensorable domain names and you wouldn't need – you could just go to whatever it is, www.anarchy or something, and then no one could ever seize that domain. 1:18:16 You could always message this person. You could always send them money, and that would be a big human rights advantage. I wrote a post called Thunder about sidechain scaling. We have the Zcash privacy sidechain already. 1:18:38 The other thing is that the design is sort of like – it's built actually to kind of steal the altcoin. So if you have an interesting altcoin node, you may be able to just capture it and run it as a BIP300 sidechain instead. There's a lot of interest in that kind of thing. 1:19:02 I like David Vork's SIA project. That's one that I bring up. We could do something with most of the NFTs. Obviously, that's sort of silly, but I think it is annoying that all of that activity is on Ethereum and not on Bitcoin. And then we have to have these tweets about how Jack Dorsey is actually using Ethereum and blah, blah, blah. So I actually think there are quite a few. And some of them are in the talk from Bitcoin 2021. 1:19:29 Okay, JW. Your response to Ben? 1:19:31 Yeah, so Ben, I think your question is actually wrong. I don't think that there is anything that could give us more utopia than Drivechains, at least if they work the way that Paul is talking about. Because he's saying stuff like, we don't have to upgrade Bitcoin again. It's possible that this is it. 1:19:50 Anything that you can do on an altcoin, you'll be able to do. Any altcoin that's ever been created, you're going to be able to do on Bitcoin. Any altcoin that's conceivable, you'll be able to do on Bitcoin. So why would we prioritize something like taproot over Drivechains? It doesn't make sense. We could have done taproot. We could have done all of the things that you could possibly imagine on a sidechain. And all we have to do is implement these two BIPs. 1:20:16 Now, that is, I think, actually true, right? I think all of that functionality does come along with giving people the ability, encouraging people to move over to a sidechain where miners can steal funds. But that's the problem. Miners can steal funds. 1:20:32 So the reason that it's not being prioritized as high as something like taproot is taproot was super, super safe by comparison. We got some stuff, not a ton of stuff, really, but it was super, super safe. Same thing with SegWit. We got some stuff, not much, right? We fixed a couple security issues. And yes, when those went away, it opened up some doors for stuff like Lightning. 1:20:55 But relatively speaking, compared to something that has all of the amazing promise of Drivechains, we didn't get much from either of those two. So the pivoting factor is how safe is it? And it's just not safe. It's got a very critical security flaw in it that's going to allow people to get really screwed over. And we want to prevent that when we can. That's the whole point of this process. 1:21:19 Ruben, Mario, you guys want to chime in? Or Ben? Nope. Anybody from our audience have a question? Otherwise, we'll call it quits. 1:21:32 Right on. Thank you, guys. Appreciate being able to hang out. 1:21:37 All right. Thanks, everyone. Take care. 1:21:40 Thanks, everyone.