Episode Details

Back to Episodes
Chat_177 - Security Is Just a Hard Problem with Lloyd Fournier

Chat_177 - Security Is Just a Hard Problem with Lloyd Fournier

Published 1 day, 7 hours ago
Description

***"I think that self custody is not going to be dead. I think that there is going to have to be a group, a vanguard of people that do this and take it seriously. The revolution won't work without that. Everything under the spectrum is acceptable. But if you know what you're here for, you got to put pressure against those systems. And that is by taking the self-custody yourself. That's why we make tools for those people."

~ Lloyd Fournier***

Self-custody is not dead, but it is a ridiculously hard problem to solve. And recent events have proven that hardware wallets are not the infallible fortresses we sometimes pretend they are. I sat down with Lloyd Fournier, the cryptographer and architect at Frostsnap, to talk about what it actually takes to secure your Bitcoin when you can't even trust your own devices.

We get straight to the weeds on how Frostsnap is rethinking multisig by using Shamir secret sharing to sign transactions without ever reconstructing the private key in one place. But we also tackle the elephant in the room: the recent Coldcard entropy vulnerability. Lloyd also explains exactly how the Dark Skippy attack works, why bad random number generation is fatal, and why hardware wallet manufacturers are ultimately trusted third parties.

We also shift gears to talk about alternative cryptography, and the magic of BLS signatures and why they completely remove the need for randomness during signing. And of course, we had to address the quantum computing threat. Is the danger real, or is it mostly academic noise? We debate the best way for Bitcoin to safely migrate if quantum computers ever actually materialize, including a really clever idea for a quantum canary bounty.

This is a must-listen if you approach self-custody with an adversarial mindset.

Chapters

(00:00:00) - Introduction

(00:06:59) - Lloyd Fournier's background and building Frostsnap

(00:19:07) - Why software is a multisig single point of failure

(00:28:22) - Dark Skippy and hardware wallets attacks

(00:33:33) - Breaking down the Coldcard entropy vulnerability

(00:43:05) - Why self-custody is mandatory for Bitcoin

(00:55:14) - BLS signatures and removing randomness from signing

(01:09:40) - The quantum computing threat

(01:18:22) - Soft forks and quantum canary bounties

(01:30:38) - Hash-based signatures and stateless cryptography

(01:41:29) - Red teaming hardware wallets using AI models

(01:51:04) - Why everyone must eventually learn self-custody

Guest Links

Lloyd on X (Link: https://twitter.com/LLFOURN)

Frostsnap on X (Link: https://twitter.com/FrostsnapTech)

Frostsnap's Website (Link: https://frostsnap.com/)

Affiliate Links

  • Become sovereign, hold your keys, be censorship resistant with the Bitbox hardware wallet. Get 5% off everything in the store with code GUY (Link: https://bitbox.swiss/)
  • Get 10% off the best Bitcoin board game in the world, HODLUP! Or any of the other great games from The Free Market Kids! Use code GUY10 at checkout for 10% off your cart! (Link: https://www.freemarketkids.com/collections/games-1)

Host Links

⁠⁠Guy on Nostr ⁠(Link: http://tinyurl.com/2xc96ney)

⁠Guy on X ⁠(Link: https://twitter.com/theguyswann)

Guy on Instagram (Link: https://www.instagram.com/theguyswann)

Guy on TikTok (Link:

Listen Now