1
00:00:00,000 --> 00:00:09,920
You've had a dynamic where money has become freer than free.

2
00:00:10,760 --> 00:00:15,680
If you talk about a Fed just gone nuts, all the central banks going nuts.

3
00:00:16,380 --> 00:00:17,860
So it's all acting like safe haven.

4
00:00:18,400 --> 00:00:23,500
I believe that in a world where central bankers are tripping over themselves to devalue their

5
00:00:23,500 --> 00:00:28,480
currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor.

6
00:00:28,480 --> 00:00:31,380
I mean, that's part of the bull case for Bitcoin.

7
00:00:31,800 --> 00:00:34,240
If you're not paying attention, you probably should be.

8
00:00:36,600 --> 00:00:39,080
Yeah, I don't think we can assume everybody's heard.

9
00:00:39,580 --> 00:00:40,040
And I know.

10
00:00:40,840 --> 00:00:47,700
I think that's a bad assumption just because I've been texting people I know have cold cards and they're completely oblivious to what was going on last night.

11
00:00:48,020 --> 00:00:49,000
So, yeah.

12
00:00:51,360 --> 00:00:52,120
Sad day.

13
00:00:53,420 --> 00:00:56,720
Yeah, we've talked under better circumstances for sure.

14
00:00:58,480 --> 00:01:21,120
For those who are unaware, there is a massive vulnerability in cold cards produced after 2021, all models, some worse than others, but essentially the random number generator that creates the entropy for private keys that you produce.

15
00:01:21,840 --> 00:01:25,880
Using the cold card is insufficient. Is that the right word?

16
00:01:25,880 --> 00:01:40,880
Yeah, you could call it deterministic. So the search space required to get the private key to guess the private key basically is highly, highly limited relative to what it should be.

17
00:01:40,880 --> 00:01:52,820
So basically the, you know, funds under the MK2, MK3s with firmware between, you know, 2021 and 2023 are just kind of like dangling in the wind.

18
00:01:52,820 --> 00:02:03,240
And so luckily, if you use dice rolls, you know, if you use, say, over 99 dice rolls to initialize the key, you're you're safe.

19
00:02:04,080 --> 00:02:13,500
And or if you're using a passphrase, which is basically like the 25th word you can specify when you're setting up the wallet.

20
00:02:13,500 --> 00:02:23,080
But if that passphrase is of a sufficient length and complexity, which is longer than most people think, then you may also be safe.

21
00:02:25,560 --> 00:02:37,980
But yeah, those the MK2, MK3s are affected severely to the point where it's like, you know, you need to drive home from work and migrate your funds.

22
00:02:37,980 --> 00:02:45,720
if you're single SIG under one of those without a passphrase, without DICE, or with a weak passphrase.

23
00:02:46,580 --> 00:02:54,040
But we're finding, and it's part of an ongoing investigation as to the current state of the cold card firmware,

24
00:02:54,560 --> 00:03:03,180
which would affect newer devices like the Q, we're finding that the problem still exists there too, but it's partially mitigated.

25
00:03:03,180 --> 00:03:18,160
So estimates right now are that current users of cold card devices are getting about 70 bits of security, whereas you're supposed to be getting 256 bits during key gen.

26
00:03:18,160 --> 00:03:39,020
But that 70-bit number is even going down because we're finding that one of the fallback RNGs that is used to paper over the original defect is actually less random than we thought and is specified by the manufacturer.

27
00:03:39,020 --> 00:03:43,820
And, you know, they may be doing things like zeroing out certain parts of this ID.

28
00:03:43,820 --> 00:03:50,460
And so it might actually be worse than we were thinking last night for current devices.

29
00:03:50,820 --> 00:03:58,360
So my headline for everybody at this point is if you're working off of a cold card device,

30
00:03:59,280 --> 00:04:05,920
after 2021, you need to migrate your funds pretty expeditiously.

31
00:04:06,420 --> 00:04:09,860
If you did all the dice rolls, don't worry.

32
00:04:11,480 --> 00:04:13,240
You're probably in good shape.

33
00:04:13,820 --> 00:04:21,600
But even so, yeah, I think, unfortunately, people should be making moves to get off of the post 2021 devices.

34
00:04:26,600 --> 00:04:32,620
Yeah, I mean, we're trying to find some humor in light of this, but cold card.

35
00:04:33,200 --> 00:04:37,460
Hey, listen, I've been an advocate for cold card for many years.

36
00:04:37,560 --> 00:04:39,240
If you listen to the show, I've recommended it.

37
00:04:39,240 --> 00:04:40,720
I have my cue right here.

38
00:04:40,880 --> 00:04:43,780
I moved my funds off last night.

39
00:04:43,820 --> 00:04:47,900
obviously a managing partner in 1031

40
00:04:47,900 --> 00:04:50,780
were invested in CoinKite, which produces the cold card.

41
00:04:51,020 --> 00:04:54,400
This is very close to home

42
00:04:54,400 --> 00:05:00,060
for me personally, to many people I know that have felt very confident

43
00:05:00,060 --> 00:05:03,720
recommending this in the past.

44
00:05:03,720 --> 00:05:19,743
It seems that the confidence was ill We were joking before It like the cold card souped up two secure enclaves but you mess up one part of it the random number generator so you get a ferrari on top of a lawnmower

45
00:05:19,743 --> 00:05:29,263
engine well pretty devastating i'm in the same boat man i mean i i'm a single sig passphrase guy

46
00:05:29,263 --> 00:05:36,383
on a cold card you know i think mark ii my firmware is older and unaffected but

47
00:05:37,503 --> 00:05:44,663
I love CoinKite. They make great products. But the unfortunate nature of security and

48
00:05:44,663 --> 00:05:48,943
hardware wallets is that you screw up one thing, you screw up the wrong one thing, and

49
00:05:48,943 --> 00:05:58,603
it's toast. And so that's the reason why people have been sort of paranoid in this

50
00:05:58,603 --> 00:06:07,083
department is because you just simply can't trust one manufacturer or one source for your entropy.

51
00:06:07,503 --> 00:06:20,383
You know, when you're doing entropy construction, and this is what I do professionally for the last few years, is you have to be utterly paranoid when you're constructing a private key.

52
00:06:20,803 --> 00:06:25,103
And you can't just click a button and expect that it'll happen, you know.

53
00:06:25,103 --> 00:06:32,123
um so it's yeah it's it's really it's really sad to see because i recommended

54
00:06:32,123 --> 00:06:40,403
cold card left and right you know um the people who i thought were savvy enough uh to use them

55
00:06:40,403 --> 00:06:48,243
and um i'd say like aside from you know getting yourself safe my message to people would be

56
00:06:48,243 --> 00:06:56,263
think about who is a sort of more normal person than maybe you are listening to this podcast who

57
00:06:56,263 --> 00:07:03,163
you've recommended cold cards to who maybe isn't like following bitcoin twitter um you know give

58
00:07:03,163 --> 00:07:08,943
them a heads up if you got them set up with a cold card um i've got a few such people in my life that

59
00:07:08,943 --> 00:07:15,723
i've reached out to yeah that's why i wouldn't that's why i hit you up last night to record this

60
00:07:15,723 --> 00:07:18,963
and I'm distracted right now because I'm about to send out a newsletter

61
00:07:18,963 --> 00:07:20,863
that just covers this as well.

62
00:07:22,363 --> 00:07:27,103
I've got to give one more prompt to my client here to make something very clear here.

63
00:07:27,363 --> 00:07:31,463
But dive into the math.

64
00:07:31,583 --> 00:07:34,023
So you mentioned later versions.

65
00:07:35,023 --> 00:07:37,723
People are saying potentially 70 bits of entropy.

66
00:07:37,983 --> 00:07:42,743
You should have 256, MK2, MK3 after 2021, even less.

67
00:07:42,843 --> 00:07:44,743
I think it's like 30 bits.

68
00:07:44,743 --> 00:07:52,903
it's 20 20 yeah and i mean the nature of the attack i mean this is obviously very much centered on on

69
00:07:52,903 --> 00:08:01,543
coin kite and cold card however um ai comes into the mix i mean this is a new era of security

70
00:08:01,543 --> 00:08:07,323
vulnerabilities and i mean we've been talking about it the better part of a couple years now

71
00:08:07,323 --> 00:08:12,423
on this show and others that these models once they get sufficiently intelligent we'll be able

72
00:08:12,423 --> 00:08:16,643
to uncover these. And it seems like that may be exactly what happened yesterday.

73
00:08:17,543 --> 00:08:23,663
It's totally plausible, man. You know, me and a number of other researchers very quickly,

74
00:08:23,823 --> 00:08:30,663
independently reproduced this just by giving the AI kind of a pointer as to, hey, you know,

75
00:08:30,663 --> 00:08:36,023
between this window of time between these firmware versions, check for an RNG problem.

76
00:08:36,023 --> 00:08:41,123
And Kimmy K3 chewed through it and found it readily.

77
00:08:43,623 --> 00:08:58,803
And, yeah, look, if you're a sort of unscrupulous attacker and you're willing to just sit there and grind through, you know, take any open source Bitcoin software you can and just say, hey, file by file, go through, look at the entire history.

78
00:09:00,783 --> 00:09:03,343
You know, find something that's plausibly an exploit.

79
00:09:03,343 --> 00:09:26,423
All that stuff's going to get unearthed. So somebody I was talking to yesterday put it this way. He said, you know, security by obscurity is going to zero rapidly and everything, you know, the tide's washing out. So it's going to be really wild a few weeks and months and probably years.

80
00:09:26,423 --> 00:09:31,943
outside of Bitcoin, Matt and I discussed

81
00:09:31,943 --> 00:09:35,683
on RHR where there was a water system in Minneapolis that was attacked

82
00:09:35,683 --> 00:09:37,743
with some vibe-coded

83
00:09:37,743 --> 00:09:43,703
LLM attack.

84
00:09:46,963 --> 00:09:51,503
How big of a setback do you think this is?

85
00:09:53,863 --> 00:09:55,283
Well, you know me, man.

86
00:09:55,283 --> 00:10:01,703
I tend to be somewhat pessimistic in the short to midterm.

87
00:10:03,903 --> 00:10:16,383
And my real worry, aside from like the horrible tragedy of a bunch of good people losing their coins, that's obviously horrible.

88
00:10:16,383 --> 00:10:30,666
I a bit worried about the second order effect of this being a hit against kind of the most reputable hardware wallet vendor

89
00:10:30,666 --> 00:10:38,566
you know, among hardcore Bitcoiners, that kind of like rippling out into a notion that, well,

90
00:10:38,606 --> 00:10:45,286
even the smart guys screwed up self-custody. And how can we expect that anybody, you know,

91
00:10:45,286 --> 00:10:53,566
will comfortably solve custody after this point. So I don't necessarily agree with that because

92
00:10:53,566 --> 00:11:00,446
again, if you kind of followed best practices that were recommended, you'd have avoided this pickle

93
00:11:00,446 --> 00:11:06,586
purely by obeying that principle that you can't trust a single manufacturer or you have to bring

94
00:11:06,586 --> 00:11:12,746
your own entropy to the table somehow. But even so, I worry this event is going to get a lot of play

95
00:11:12,746 --> 00:11:16,046
and maybe the general public

96
00:11:16,046 --> 00:11:16,906
is going to be like,

97
00:11:16,986 --> 00:11:17,926
oh yeah, that Bitcoin thing,

98
00:11:18,006 --> 00:11:19,826
that's impossible to keep safe by yourself.

99
00:11:20,226 --> 00:11:22,226
So just got to use a custodian.

100
00:11:23,026 --> 00:11:24,306
I mean, the irony of the whole situation

101
00:11:24,306 --> 00:11:25,926
is with all the eyes

102
00:11:25,926 --> 00:11:28,246
and compute focused on

103
00:11:28,246 --> 00:11:32,966
the cold card repository right now

104
00:11:32,966 --> 00:11:33,846
by the end of the week

105
00:11:33,846 --> 00:11:37,606
and maybe the most secure system

106
00:11:37,606 --> 00:11:39,206
in the space.

107
00:11:39,946 --> 00:11:41,746
But again, the trust is...

108
00:11:42,746 --> 00:11:44,486
Very hard to build, very easy to break.

109
00:11:45,926 --> 00:11:47,726
Yeah, and that's the problem.

110
00:11:49,426 --> 00:11:59,346
And, you know, in some ways, this is a sort of inexcusable error if you are a company making the product that they make.

111
00:11:59,346 --> 00:12:07,666
And so, you know, again, the CoinKite guys are friends of ours, certainly of yours and mine.

112
00:12:07,666 --> 00:12:14,106
And even so, it's like, I think, huh?

113
00:12:14,786 --> 00:12:15,546
What the fuck?

114
00:12:16,166 --> 00:12:21,646
Yeah, it's going to be hard to trust anything that comes out of that brand anymore, you know.

115
00:12:24,446 --> 00:12:35,666
So it's, you know, I mean, the thing like, it feels like every single hardware wallet manufacturer has made some kind of like fatal misstep.

116
00:12:35,666 --> 00:12:41,506
this step again because this domain is just very hard you know let a ledger spilled you know all of

117
00:12:41,506 --> 00:12:49,426
their clients information essentially back what was that like 20. twice okay yeah yeah probably most

118
00:12:49,426 --> 00:12:57,986
multiple times you know bitbox had some pretty um pretty obvious physical defects that allowed key

119
00:12:57,986 --> 00:13:05,246
exfiltration. I don't know specifically if anything has befallen Trezor or not. But,

120
00:13:05,486 --> 00:13:14,206
you know, it's just it's kind of the nature of the game that these things get hit with something.

121
00:13:15,106 --> 00:13:21,286
And even if they aren't obviously hit with something, the very fact that it's a security

122
00:13:21,286 --> 00:13:25,086
critical Bitcoin device means that their whole supply chain is probably targeted.

123
00:13:25,086 --> 00:13:29,226
The companies themselves are targeted for for intervention. So.

124
00:13:31,786 --> 00:13:36,586
Custody is tough, man. It's really tough. And.

125
00:13:37,826 --> 00:13:45,026
I spent many years, you know, hoping we could make it easier with better scripting primitives and covenants and vaults.

126
00:13:45,966 --> 00:13:53,466
But, you know, I think given the community is more fractured than ever, I'm not sure we're going to get there and certainly not in the next year or two.

127
00:13:53,466 --> 00:13:55,206
but I don't know.

128
00:13:55,206 --> 00:13:58,366
I think I think this may light a fire in our people's ass to figure that

129
00:13:59,066 --> 00:14:00,606
figure out how to get that stuff through.

130
00:14:00,606 --> 00:14:02,606
I mean, a lot of

131
00:14:02,606 --> 00:14:05,106
the conversation there's back and forth people on both sides of the aisle.

132
00:14:05,106 --> 00:14:06,706
Like now is not the time to talk about this.

133
00:14:06,706 --> 00:14:08,406
And I think.

134
00:14:08,406 --> 00:14:11,426
Alex B from

135
00:14:11,426 --> 00:14:13,126
from Arc Labs

136
00:14:14,026 --> 00:14:15,566
Arcade was making some good points.

137
00:14:15,566 --> 00:14:18,166
It's like, hey, like, don't worry about obscure covenants

138
00:14:18,166 --> 00:14:21,666
when we haven't even verified like random number generation on

139
00:14:21,666 --> 00:14:24,606
some of these wallet providers.

140
00:14:25,386 --> 00:14:28,206
There's a point there, but again, you're going to,

141
00:14:28,626 --> 00:14:32,926
there's a sort of inescapable point, which is that like, you know,

142
00:14:32,966 --> 00:14:37,346
even if you supposedly verify all the RNGs, like you just can't, you, again,

143
00:14:37,406 --> 00:14:40,286
you can't trust one manufacturer, even, you know, like, look,

144
00:14:40,366 --> 00:14:44,946
I'll pick on say BitKey because that's being touted as like a,

145
00:14:44,946 --> 00:14:46,346
a migration target.

146
00:14:46,346 --> 00:14:50,126
And I think the world of that team, and I know a lot of the guys who wrote that,

147
00:14:50,126 --> 00:14:56,366
They're super smart, but, you know, like, are you really auditing their whole software stack?

148
00:14:57,026 --> 00:15:04,066
You know, like BitKey requires on-device software, you know, it's closed source.

149
00:15:04,546 --> 00:15:09,066
I know a lot of it is open source, but some of their black-end services are closed source.

150
00:15:09,066 --> 00:15:22,846
So it's like, you know, until you move some of that security into the chain itself, you're not going to be able to, like, trust one provider.

151
00:15:24,926 --> 00:15:30,886
And that until we get until we solve that, you know, it's like, OK, well, all right.

152
00:15:30,886 --> 00:15:48,249
So I go to two providers I set up a multi for myself So that that kind of a horrible user experience or a worse one for sure So while yeah I mean Alex point is taken that like there are fish to fry in the auditing department

153
00:15:49,928 --> 00:15:58,909
I think the only categorical fix for a much better UX and multisig level security is going to be something at the covenant layer.

154
00:15:58,909 --> 00:16:02,569
So that's why it's important to kind of keep focus on that.

155
00:16:02,569 --> 00:16:09,569
I do think focus will be coming back to Covenants pretty strongly here.

156
00:16:09,769 --> 00:16:12,129
That's my gut feeling.

157
00:16:13,168 --> 00:16:23,889
And as we've discussed throughout the years, I mean, the Covenants vault conversation has been probably the most consistent, continuous thread that we've had on this show.

158
00:16:23,889 --> 00:16:27,969
The conversation that you and I have had on the show over the last two or three years.

159
00:16:28,909 --> 00:16:34,348
i don't think it is time to have that conversation but i mean bringing this back to like llms and

160
00:16:34,348 --> 00:16:40,749
security that's that's another frustrating thing is like in your mind as somebody who is

161
00:16:42,029 --> 00:16:50,109
a protocol engineer or somebody's building custody systems for enterprises what is the importance of

162
00:16:50,989 --> 00:16:54,428
usually fuzz testing your system with the latest models as soon as they're dropped

163
00:16:54,428 --> 00:17:10,769
Yeah, I'm doing it all the time now, both on the level of like analysis, as well as generating, you know, permanent test fixtures that are really solid, which is that's a total blessing.

164
00:17:10,769 --> 00:17:19,708
It's easier than ever to say, hey, cross test every cryptographic implementation I'm relying on against like two or three other alternatives.

165
00:17:19,708 --> 00:17:23,329
Make sure everything marries up, you know.

166
00:17:23,329 --> 00:17:29,889
oh, and then by the way, run a full audit of my entire system at both the conceptual level

167
00:17:29,889 --> 00:17:37,429
and implementation level. Like that's incredible. And those are the same tools, obviously that enable,

168
00:17:37,669 --> 00:17:43,988
you know, unearthing these kinds of attacks. And so it's the arms race. Like if you're not

169
00:17:43,988 --> 00:17:51,129
a diligent user of the latest AI models and techniques, and you're building this stuff,

170
00:17:51,129 --> 00:17:58,169
then you're at a real disadvantage. And it really points you back in the direction of,

171
00:17:58,169 --> 00:18:01,369
man, this stuff has to be simple and rock solid.

172
00:18:01,369 --> 00:18:11,208
And it's incredibly frustrating. I mean, in parallel to all this happening, we have like the

173
00:18:13,049 --> 00:18:17,849
model wars here in the US and the government stepping in and cucking like Fable 5 and

174
00:18:17,849 --> 00:18:22,968
chat gpd 5.6 and so that's it's like if you're trying to audit these systems you can't use the

175
00:18:22,968 --> 00:18:28,968
american frontier models because you get immediately nerfed and you're forced to figure out a way to

176
00:18:28,968 --> 00:18:36,409
get access to kimi k3 which i think many people are assuming that that is the model that was used

177
00:18:36,409 --> 00:18:46,728
to discover and then exploit this particular vulnerability with cold carb um and uh

178
00:18:47,849 --> 00:18:51,688
What are we doing in the US?

179
00:18:51,688 --> 00:18:57,448
Like the Operation Glasswing, because I know many Bitcoin teams are like, hey, Anthropic,

180
00:18:57,448 --> 00:19:00,769
we have a pretty important system over here in Bitcoin.

181
00:19:00,769 --> 00:19:06,508
Can we get access to this to make sure that we're audited and finding any vulnerabilities

182
00:19:06,508 --> 00:19:08,329
or bugs that may exist?

183
00:19:08,329 --> 00:19:14,169
And I've heard that some teams in space and maybe even core developers got access to it.

184
00:19:14,169 --> 00:19:20,409
But when it comes to something like a system like Bitcoin, we need the ability to audit

185
00:19:20,409 --> 00:19:21,609
this immediately now.

186
00:19:21,609 --> 00:19:30,269
I think people really need to get through their minds that the landscape of defensive

187
00:19:30,269 --> 00:19:31,789
technology has completely shifted.

188
00:19:32,309 --> 00:19:37,829
And the way in which you secure your systems has changed.

189
00:19:38,169 --> 00:19:43,409
And it's being proactive and consistently proactive from here on out.

190
00:19:44,169 --> 00:20:03,109
100%. I was using Kimmy exclusively last night to do the triage and investigation. And I was working with some colleagues and the US-based models were just shutting, blocking up, refusing to go further on certain lines of inquiry.

191
00:20:03,109 --> 00:20:09,728
um you know i don't have a lot to say about the policy side i'm i'm i haven't thought much about

192
00:20:09,728 --> 00:20:17,968
that um i'm sort of a freedom guy and uh you know i i bless i feel feel blessed that we have vpn

193
00:20:17,968 --> 00:20:24,589
technology but um yeah the the fact of the matter is if you're not kind of on the bleeding edge and

194
00:20:24,589 --> 00:20:32,609
you're doing security stuff you're at a real disadvantage yeah um bringing this back to cold

195
00:20:32,609 --> 00:20:37,349
card walking through many scenarios like just thinking of the questions that many people

196
00:20:37,349 --> 00:20:41,109
were just becoming aware of this may have in their mind let's like walk through the scenarios

197
00:20:41,109 --> 00:20:49,968
like going from mk3 past 2021 and like obviously mk4 mk5 q

198
00:20:50,011 --> 00:20:57,931
what's the difference in terms of vulnerability exposure and urgency to move coins and then

199
00:20:57,931 --> 00:21:04,691
beyond that you mentioned the dice so to be clear if you set up a cold card and you added you brought

200
00:21:04,691 --> 00:21:08,751
your own entropy by rolling dice if you did it more than 100 times you're very confident that

201
00:21:08,751 --> 00:21:15,431
you did you should be good you basically rolled your own entropy and are not affected by the

202
00:21:15,431 --> 00:21:22,771
the rng bug that exists on the firmware or existed on the firmware yes they have updated the firmware

203
00:21:22,771 --> 00:21:30,491
um so you can update that too um for mk4 mk5 and q if you want to um

204
00:21:30,491 --> 00:21:38,431
get on get on something that's more secure than what existed yesterday but if you do that if you

205
00:21:38,431 --> 00:21:41,731
just update the firmware that doesn't make you secure you have to create a new private public

206
00:21:41,731 --> 00:21:47,851
key pair and move the Bitcoin from your existing wallet to that new wallet that you set up there.

207
00:21:48,551 --> 00:21:54,151
Yeah. The key point right there is it's not the firmware that's currently running on your

208
00:21:54,151 --> 00:22:00,131
device. It's what you generated your key with. So I could see that tripping some people up.

209
00:22:00,791 --> 00:22:09,271
Yeah. But yeah, we initially thought the red zone was basically cold cards from 21 to 23.

210
00:22:09,271 --> 00:22:17,271
that footprint has expanded because we're hearing about mk4s that have been uh stolen from and we

211
00:22:17,271 --> 00:22:23,651
have some indications of why that might be um but again to reiterate at this point you know

212
00:22:23,651 --> 00:22:29,891
if if you've generated a single sig with no passphrase no dice roll on a wind kite device

213
00:22:29,891 --> 00:22:37,731
post 21 you know you got to get off um pretty expeditiously yes um

214
00:22:39,271 --> 00:22:46,031
Multi-sig. I've talked to a number of people that are using cold cards in a multi-sig setup.

215
00:22:46,211 --> 00:22:51,091
Some are using two MK3s and a two out of three. What are the intricacies there?

216
00:22:51,271 --> 00:22:55,111
There's some nuance depending on if you've ever spent from that wallet, if you haven't.

217
00:22:56,971 --> 00:23:01,071
So if you have a two to three multi-sig using two MK3s or an MK3 and MK4,

218
00:23:01,071 --> 00:23:07,591
just go through those different scenarios. You've only sent Bitcoin to, you've never spent from,

219
00:23:07,591 --> 00:23:10,931
or you've both sent Bitcoin to and spend from?

220
00:23:11,071 --> 00:23:13,051
What is the exposure there?

221
00:23:14,051 --> 00:23:16,991
Yeah, so multi-sig is where it gets pretty complicated.

222
00:23:18,191 --> 00:23:20,731
I think it had helped to maybe step back

223
00:23:20,731 --> 00:23:23,671
and just explain a little bit how multi-sig works

224
00:23:23,671 --> 00:23:29,211
or pay-to-win to script hash or taproot scripts

225
00:23:29,211 --> 00:23:30,391
in general in Bitcoin.

226
00:23:30,671 --> 00:23:33,011
When you spend from a multi-sig,

227
00:23:33,011 --> 00:23:36,011
you actually have to present the script

228
00:23:36,011 --> 00:23:42,251
that locked up the coins in the first place, which means you have to present the pub key

229
00:23:42,251 --> 00:23:51,771
for each key involved in the multi-sig. And so what that can mean is if you're using a multi-sig

230
00:23:51,771 --> 00:24:01,611
with all cold cards and you've used, say, that address before, you've revealed all of your pub

231
00:24:01,611 --> 00:24:08,291
keys. And so an attacker could theoretically grind out all the private keys, you know, and

232
00:24:08,291 --> 00:24:15,211
construct a valid spend and be able to present a valid signature or a valid script.

233
00:24:16,871 --> 00:24:26,711
If you have a multi-sig quorum where you have like any device that isn't a cold card or a coin

234
00:24:26,711 --> 00:24:34,031
kite product, and that has to be part of the critical spend threshold, then you're in good

235
00:24:34,031 --> 00:24:41,971
shape. Basically, your coins are protected by that segment of the multi-sig. So, for example,

236
00:24:41,971 --> 00:24:50,371
if you have like a three of five and you have, not that I hope anybody out there as a consumer

237
00:24:50,371 --> 00:24:57,071
has a three to five, but three or five, but, you know, that would require signing with a device

238
00:24:57,071 --> 00:25:00,971
that isn't a coin kite device affected by this. So you'd be, you'd be in good shape.

239
00:25:03,791 --> 00:25:10,691
If for example, you're like an unchained customer, let's say, and you're doing a two of three.

240
00:25:12,251 --> 00:25:18,591
And let's say that you yourself used two affected cold cards at home. That's sort of an interesting

241
00:25:18,591 --> 00:25:27,771
situation because depending on what unchained does, their pub key may or may not be on the

242
00:25:27,771 --> 00:25:33,131
chain. I don't know. They'd be able to field this question. If their pub key is available,

243
00:25:33,131 --> 00:25:43,551
then you are vulnerable. So I think the safe guidelines there are basically if in your

244
00:25:43,551 --> 00:25:50,251
multi-sig, you have a situation where you could move the coins with only coin kite products,

245
00:25:50,251 --> 00:25:55,631
I would move to get off of that. Because there are a lot of subtleties around, well,

246
00:25:55,831 --> 00:26:09,328
you know are the hub keys out there Aren they out there Don get too clever by half And you know if you have a critical threshold of your multisig that can be provided by CoinShare products

247
00:26:09,328 --> 00:26:12,168
I would just move, don't think twice.

248
00:26:13,848 --> 00:26:16,808
So that's the long short answer there.

249
00:26:16,808 --> 00:26:21,808
And what is the assumed time you,

250
00:26:23,628 --> 00:26:27,348
like again, multisig 203, two MK3s,

251
00:26:27,348 --> 00:26:32,348
maybe the pub keys exposed,

252
00:26:32,348 --> 00:26:35,168
but compared to just a single SIG MK3,

253
00:26:35,168 --> 00:26:39,148
no bring your own entropy, no passphrase.

254
00:26:39,148 --> 00:26:41,468
I've heard that if you have multi-SIG,

255
00:26:41,468 --> 00:26:42,828
you probably have a couple of days

256
00:26:42,828 --> 00:26:44,768
the way these attacks are.

257
00:26:44,768 --> 00:26:49,248
Yeah, that's my inclination to say,

258
00:26:49,248 --> 00:26:52,148
but with this stuff, you kind of have to assume

259
00:26:52,148 --> 00:26:53,968
that now that the vulnerability is out there,

260
00:26:53,968 --> 00:26:56,748
that the entire internet is gonna be just like

261
00:26:56,748 --> 00:27:02,868
grinding on this. And so, yeah, multi-sig is harder to scan for for an attacker, but that's

262
00:27:03,868 --> 00:27:11,828
just a shallow throw more compute at it type problem. Yeah. And I wouldn't back up to that.

263
00:27:12,088 --> 00:27:18,768
And let me reiterate there when I say, you know, if you have a critical threshold of coin kite

264
00:27:18,768 --> 00:27:23,808
devices able to sign for your multi-sig, that is assuming you didn't use dice, you don't have

265
00:27:23,808 --> 00:27:28,768
passphrase and so on and so forth. That's just a kind of naive, you know, single SIG. So,

266
00:27:28,828 --> 00:27:33,988
so don't, if, if you've used 99 dice rolls, you know, on, on some of your coin kite keys,

267
00:27:33,988 --> 00:27:41,108
I have verified by hand that that code path is safe. So you're okay. Um, don't worry about those.

268
00:27:41,348 --> 00:27:45,648
It's really just, yeah, if you just trusted the device to, to give you a good key.

269
00:27:47,728 --> 00:27:49,528
Oh, um,

270
00:27:49,528 --> 00:27:58,048
i'm trying to think of all the scenarios that

271
00:27:58,048 --> 00:28:04,448
oh the the one question like have you heard of any white hats

272
00:28:04,448 --> 00:28:10,728
going after this because it's going to be messy and there was some discussion there was a twitter

273
00:28:10,728 --> 00:28:15,628
space this last night i was listening in on him it was a the moral conundrum a lot of people were

274
00:28:15,628 --> 00:28:19,528
discussing, like, should we run GPU and just sweep the people that are exposed?

275
00:28:22,748 --> 00:28:30,668
Yeah, that's a, that's an ethically gray area that I haven't sat down and put the

276
00:28:30,668 --> 00:28:35,408
right amount of consideration into. I have been contacted by people with prospective

277
00:28:35,408 --> 00:28:40,908
plans for that. I don't know if it's actively happening.

278
00:28:40,908 --> 00:28:48,668
there's obviously the problem of attribution. You know, if you do sweep those funds as a white hat,

279
00:28:48,808 --> 00:28:56,128
how do you then verify back? There's some indication that given into UID, if you bring

280
00:28:56,128 --> 00:29:04,548
the physical device, exactly. If you can present, you know, but that's, you know, the mechanism for

281
00:29:04,548 --> 00:29:12,728
that hasn't been demonstrated to me conclusively. So on the one hand, it's very difficult.

282
00:29:13,468 --> 00:29:19,108
And I personally wouldn't be rushing out to white hat this. But on the other hand,

283
00:29:19,808 --> 00:29:25,728
the real argument for that kind of thing is that there are a lot of users out there who are affected

284
00:29:25,728 --> 00:29:33,308
by this, who probably are not listening to podcasts and browsing Bitcoin Twitter. And those

285
00:29:33,308 --> 00:29:38,268
of the guys that are going to get ground down over the next few weeks if they're not made aware

286
00:29:38,268 --> 00:29:46,028
of the situation. And so that's a real tricky one. Yeah. There's a big ethical dimension to that one

287
00:29:46,028 --> 00:29:53,228
as well as probably like a legal dimension that you need to think through. Yeah. Yeah.

288
00:29:53,228 --> 00:30:00,708
I mean

289
00:30:00,708 --> 00:30:02,708
that's like

290
00:30:02,708 --> 00:30:03,548
does the

291
00:30:03,548 --> 00:30:07,368
does the

292
00:30:07,368 --> 00:30:12,228
collapse in confidence of

293
00:30:12,228 --> 00:30:14,008
the

294
00:30:14,008 --> 00:30:16,248
coin cake hold cards

295
00:30:16,248 --> 00:30:20,408
lead to like a lack of confidence in other

296
00:30:20,408 --> 00:30:22,528
and like it goes back to the importance

297
00:30:22,528 --> 00:30:29,888
like I've been a big believer of multi-vendor multi-sig for this exact reason for for many years

298
00:30:29,888 --> 00:30:37,228
since it's like there's a bunch of people wondering like okay cold card I don't have a

299
00:30:37,228 --> 00:30:41,248
cold card but I'm looking at my treasurer look at my ledger like are these okay and we should

300
00:30:41,248 --> 00:30:49,368
worry like I think no you shouldn't be worried as of right now and maybe we won't ever have to be

301
00:30:49,368 --> 00:30:55,388
worried there's the potential that the way they do their entropy and create their private public

302
00:30:55,388 --> 00:31:02,568
key pairs is is really top-notch and gives you uh enough it gives you 256 bits of of entropy that

303
00:31:02,568 --> 00:31:08,948
is secure and very hard and impossible to break statistically uh improbable to break um

304
00:31:08,948 --> 00:31:20,224
and so if you out there in that situation like do not panic that what i would say Yeah That because that one of the other big mistakes that many people will make

305
00:31:20,304 --> 00:31:27,204
Many people will lose coins by panicking and foot gunning themselves in the process of trying to sweep coins or something like that.

306
00:31:27,824 --> 00:31:28,024
Yeah.

307
00:31:28,064 --> 00:31:33,324
You always want to be doing test transactions of small amounts whenever you're sending anywhere, you know.

308
00:31:34,864 --> 00:31:37,504
And that's crucial to keep in mind.

309
00:31:37,504 --> 00:31:38,504
Yeah.

310
00:31:40,004 --> 00:31:43,064
throughout all this if you're migrating your own stuff.

311
00:31:45,364 --> 00:31:51,324
How do we know that exchanges have secure setups?

312
00:31:52,464 --> 00:31:56,444
Well, I know that a few do firsthand.

313
00:31:56,444 --> 00:32:14,504
But. Yeah, I am not aware of any exchanges that, you know, would be vulnerable to this.

314
00:32:14,504 --> 00:32:29,824
And I would like to think that almost every exchange has put more thought into entropy generation than, hey, we're going to click a button on a consumer device and hope for the best.

315
00:32:29,824 --> 00:32:47,504
Um, but, uh, this, you know, I, this is a wake up call for everybody, including enterprises that, um, you really have to put tremendous amount of care and thought into this part of the process.

316
00:32:47,504 --> 00:33:07,284
And what I've always tried to emphasize to clients is you need at least one component of your entropy that you can physically reason about and that you understand in terms of how it's being incorporated into the entropy.

317
00:33:07,284 --> 00:33:14,144
And so I think probably guys like us, consumers are going to have to start to think about this.

318
00:33:14,144 --> 00:33:26,704
You know, how do we take a very simple piece of code, you know, that we can reason about or have audited by somebody we trust and say, oh, yeah, this is a part of the key now for sure.

319
00:33:27,624 --> 00:33:32,684
Because, yeah, I can see how this event would keep you up at night.

320
00:33:32,764 --> 00:33:34,584
You say, well, why? Why couldn't this happen to Ledger?

321
00:33:34,664 --> 00:33:36,824
Why couldn't this happen to Trezor?

322
00:33:36,824 --> 00:33:45,824
You know, what I will say is that like CoinKite was a very lean, is a very lean company.

323
00:33:45,824 --> 00:33:59,824
And most other hardware wallet manufacturers, certainly Ledger and Trezor have pretty big teams, you know, who are doing a lot of internal auditing.

324
00:33:59,824 --> 00:34:02,824
I mean, Ledger's, you know, there are some phenomenal people there.

325
00:34:02,824 --> 00:34:04,824
This isn't an advertisement for Ledger or anything.

326
00:34:04,824 --> 00:34:14,124
I don't even use a ledger personally, but there are some phenomenal people there who have done some very novel hardware attacks.

327
00:34:15,404 --> 00:34:16,604
The Don John team.

328
00:34:16,764 --> 00:34:17,264
It's like it's.

329
00:34:17,684 --> 00:34:18,164
Yeah.

330
00:34:18,724 --> 00:34:19,644
Joke last night.

331
00:34:19,744 --> 00:34:23,644
It's like they figured out a way to use two hundred fifty thousand dollars lasers to hack a cold car.

332
00:34:23,784 --> 00:34:24,604
But it was.

333
00:34:27,404 --> 00:34:27,844
Yeah.

334
00:34:28,124 --> 00:34:28,504
Yeah.

335
00:34:28,904 --> 00:34:29,284
Exactly.

336
00:34:31,464 --> 00:34:32,944
So, yeah, I mean.

337
00:34:32,944 --> 00:34:34,104
Yeah.

338
00:34:34,824 --> 00:34:43,244
I still think a multi-manufacturer approach for guys like us is a really solid approach.

339
00:34:43,244 --> 00:34:55,524
But as Nick Szabo said, it just echoes all the time, trusted third parties are security holes.

340
00:34:56,364 --> 00:35:04,444
And for something like this, there's a certain level you can't delegate to a packaged product.

341
00:35:04,824 --> 00:35:15,944
Not easy, man. It's really not easy, especially at the enterprise level, thinking about this stuff and designing it. It's a tough thing.

342
00:35:15,944 --> 00:35:20,124
Well, trying to find the silver lining in all this.

343
00:35:20,124 --> 00:35:21,044
I mean, it is.

344
00:35:24,724 --> 00:35:25,324
Horrible.

345
00:35:26,544 --> 00:35:27,544
Disasterous.

346
00:35:29,224 --> 00:35:31,264
But something that Bitcoiners have said for a while,

347
00:35:31,424 --> 00:35:35,584
Bitcoin creates this honeypot to surface these vulnerabilities

348
00:35:36,544 --> 00:35:39,624
because the ability to.

349
00:35:39,624 --> 00:35:42,904
Send the bearer asset and actually have control of it

350
00:35:42,904 --> 00:35:44,464
with no clawbacks,

351
00:35:44,904 --> 00:35:46,924
price that incentive to find these vulnerabilities.

352
00:35:47,164 --> 00:35:48,424
Now with the AI tools,

353
00:35:48,504 --> 00:35:50,024
obviously that is accelerating.

354
00:35:50,564 --> 00:35:54,384
So I'd be interested to get your thoughts

355
00:35:54,384 --> 00:35:55,244
as there's silver lining

356
00:35:55,244 --> 00:35:56,584
where we're going to find these vulnerabilities.

357
00:35:57,404 --> 00:35:59,584
And obviously there's already been collateral damage.

358
00:35:59,724 --> 00:36:01,684
There's likely going to be more collateral damage

359
00:36:01,684 --> 00:36:02,544
in the weeks to come.

360
00:36:02,544 --> 00:36:03,864
But on the other side,

361
00:36:05,064 --> 00:36:09,624
it's darkest before the dawn.

362
00:36:09,804 --> 00:36:10,424
On the other side,

363
00:36:10,484 --> 00:36:12,324
could you see Bitcoin actually being

364
00:36:12,324 --> 00:36:17,064
significantly more secure and the products around it being more secure a

365
00:36:17,064 --> 00:36:21,144
year from now because of the wake-up call that we just got in the last 24

366
00:36:21,144 --> 00:36:37,580
hours yeah it possible this could be like a step along the anti path to essentially discovering the final form right of individual level Bitcoin security

367
00:36:37,580 --> 00:36:43,340
because it's possible that we could get to some kind of deterministic endpoint where,

368
00:36:43,340 --> 00:36:49,420
you know, there's a system or a set of software or an arrangement where, you know,

369
00:36:49,680 --> 00:36:53,840
humans, machines have done all the analysis and have said, yeah, I mean,

370
00:36:54,180 --> 00:37:01,680
if you do it this way with this binary on this platform, like, you know, if it's simple enough,

371
00:37:01,680 --> 00:37:08,860
we could get to a point where ultimately this event has catalyzed a bunch of people to put

372
00:37:08,860 --> 00:37:16,240
put the effort in and create something where you truly can't be hacked unless you get

373
00:37:16,240 --> 00:37:24,120
you know some physical component and then even then you know if if something like this motivates

374
00:37:24,120 --> 00:37:29,540
a re-interest in vaults well even if you do get hacked then you have a

375
00:37:29,540 --> 00:37:35,300
six hour window to, to claw into a, you know, a trusted counterparty, like an exchange.

376
00:37:37,600 --> 00:37:45,120
So, yeah, I think conceivably this, this could be the kind of kick in the butt that the industry

377
00:37:45,120 --> 00:37:52,860
needed to start thinking about some of that stuff. I, you know, there's a long timeline on that. And

378
00:37:52,860 --> 00:38:02,680
right now the community is pretty fractured so um uh i don't know yeah i will say i mean

379
00:38:02,680 --> 00:38:07,940
in terms of like protocol development it certainly is fractured but another silver lining i mean it

380
00:38:07,940 --> 00:38:14,900
was encouraging to see people come together publicly behind the scenes i mean i think it

381
00:38:14,900 --> 00:38:22,040
was i mean i was in dc at an event at pub key and like at the beginning of it i was like oh

382
00:38:22,040 --> 00:38:25,560
what's going on then it became clear what's going on it was just like in the corner on my phone the

383
00:38:25,560 --> 00:38:32,480
whole night like all right all hands on deck and i think there was um it's weird too with bitcoin

384
00:38:32,480 --> 00:38:38,480
there is no ceo to call so it's like people like rob hamilton yourself um portland huddle others

385
00:38:38,480 --> 00:38:44,300
hopping on spaces to try to educate people about all this and i know behind the scenes many people

386
00:38:44,300 --> 00:38:52,040
reaching out one node to many like hey my guy i uh wound up texting a friend

387
00:38:52,040 --> 00:38:56,500
um being like hey are you aware of this he's like no i've been heads down all day

388
00:38:56,500 --> 00:39:06,600
and his brother um is a is a coin or two and was on vacation and like he was able to like go over

389
00:39:06,600 --> 00:39:12,920
to his house like and he had he just sit on a bare single cg mk3 with no dysentropy or passphrase

390
00:39:12,920 --> 00:39:18,120
was able to like move it and so that like was like okay and i think there was much of that going on um

391
00:39:19,320 --> 00:39:24,280
and i think that's the spirit that um we need to lean into heavily particularly as this is

392
00:39:24,280 --> 00:39:31,240
unfolding is obviously there's going to be a lot of uh justifiably angry angry people um

393
00:39:32,120 --> 00:39:38,360
very very much justified but um i don't think this is the time like sling and

394
00:39:38,360 --> 00:39:40,300
and throw people under the bus.

395
00:39:40,380 --> 00:39:41,680
It's like, okay, this is happening.

396
00:39:42,040 --> 00:39:45,560
While it's happening, let's just make sure we get as many people

397
00:39:45,560 --> 00:39:49,200
out of harm's way as possible.

398
00:39:51,260 --> 00:39:52,180
Totally agree.

399
00:39:53,940 --> 00:39:59,300
And this thing is still ongoing, so it's still critical to give people heads up

400
00:39:59,300 --> 00:40:05,360
and just be racking your brain for anybody who may not be listening to podcasts

401
00:40:05,360 --> 00:40:12,440
uh, you know, who has a cold card. Um, because I think probably we're going to continue to see,

402
00:40:12,440 --> 00:40:22,320
uh, you know, funds flow around. Um, so, uh, yeah, I mean, it's, it's, it's hard to,

403
00:40:22,320 --> 00:40:25,920
this, the sentiment thing's difficult because like, there is a kind of like,

404
00:40:26,500 --> 00:40:33,820
um, excitement and camaraderie that comes out of an event like this, but that we, we can only

405
00:40:33,820 --> 00:40:39,800
experienced that because we didn't lose our life savings, you know, and there are people

406
00:40:39,800 --> 00:40:48,220
that happened to, um, and that's horrible. Uh, that's really horrible. Um, it's not,

407
00:40:48,380 --> 00:40:56,560
it's not the worst thing. You know, um, if you're one of those people, uh, God has a plan and,

408
00:40:56,560 --> 00:41:02,640
um, you need to keep that in mind. Um,

409
00:41:03,820 --> 00:41:25,380
But, yeah, it is good to see the community kind of reorient in certain ways and come back to, you know, the real stuff of Bitcoin rather than, you know, gathering about 110 or whatever.

410
00:41:25,380 --> 00:41:26,380
No.

411
00:41:26,380 --> 00:41:29,380
I think we need to keep the shore.

412
00:41:29,380 --> 00:41:30,380
Is there anything we missed?

413
00:41:30,380 --> 00:41:32,380
We should be getting out there.

414
00:41:32,380 --> 00:41:37,380
I mean, it's probably we should keep it short so we can get out there to people as quickly

415
00:41:37,380 --> 00:41:38,380
as possible.

416
00:41:38,380 --> 00:41:39,960
No, I mean, I think we hit the headline.

417
00:41:39,997 --> 00:41:47,097
You know, there's obviously tons of technical detail you go into, but the investigation is still ongoing.

418
00:41:47,097 --> 00:42:03,157
So, you know, again, my headline is if you have a coin kite device post 2021 and you didn't use dice rolls, don't have a super strong passphrase that, you know, is cryptographically strong.

419
00:42:03,357 --> 00:42:06,697
You know, you need to expedite getting your funds.

420
00:42:06,697 --> 00:42:11,677
My, you know, my recommend recommendation for a lot of people would be find an exchange that you trust.

421
00:42:12,757 --> 00:42:20,637
And just if you don't mind doxing yourself, park park your funds there while you figure out what the long term is and just kind of get out of Dodge.

422
00:42:21,737 --> 00:42:23,357
Do a small test transaction.

423
00:42:24,797 --> 00:42:27,837
You know, don't don't panic.

424
00:42:28,117 --> 00:42:30,197
Don't don't rush anything.

425
00:42:30,197 --> 00:42:32,197
But, you know.

426
00:42:36,697 --> 00:42:38,017
Steady is smooth.

427
00:42:38,117 --> 00:42:38,837
Smooth is fast.

428
00:42:39,557 --> 00:42:39,677
Yeah.

429
00:42:42,077 --> 00:42:45,757
Just to clarify, if you're sitting there, like, did I roll the dice enough?

430
00:42:45,957 --> 00:42:47,337
Is my passphrase strong enough?

431
00:42:47,497 --> 00:42:53,517
If you have 99 or more dice rolls and you did it correctly, you're confident in that, you should be fine.

432
00:42:54,477 --> 00:43:00,657
Passphrase, if you have six or more VIP 39 words as a passphrase, you should be good.

433
00:43:00,657 --> 00:43:06,417
Is that the thresholds that are correct there in my mind?

434
00:43:06,697 --> 00:43:15,017
sorry repeat uh uh password criteria six six bit 39 words or more um

435
00:43:19,097 --> 00:43:24,777
uh maybe i i wouldn't uh i wouldn't enjoy on that per se because there you know

436
00:43:24,777 --> 00:43:31,977
there are things like are you mixing case for that um uh you know each bit 39 word is like a

437
00:43:31,977 --> 00:43:47,320
drawn from a set of 2048 So 2048 times six isn a big search space That why passphrases are tough because something you might think is pretty strong like given enough GPUs is not

438
00:43:47,320 --> 00:43:54,600
Okay. So unless you're like a specialist and you know your passphrase is like crazy and strong,

439
00:43:54,600 --> 00:44:03,840
I would not rely on that. I'll be moving my small number of fractional Bitcoin around,

440
00:44:05,120 --> 00:44:11,040
even though I'm not affected by the firmware version and I have a strong passphrase. But

441
00:44:11,040 --> 00:44:14,500
even so, out of an abundance of caution, I'm just going to be moving.

442
00:44:15,840 --> 00:44:21,280
All right. Well, I hate that we had to meet here under these circumstances,

443
00:44:21,280 --> 00:44:24,820
but I really appreciate that you hopped on to walk through this.

444
00:44:24,820 --> 00:44:27,980
We'll get this out and warn people about all this.

445
00:44:28,620 --> 00:44:31,480
Of course, man. Yeah. Good to see you.

446
00:44:32,480 --> 00:44:33,840
Good to see you too. Peace and love, freaks.

447
00:44:34,420 --> 00:44:37,380
Thank you for listening to this episode of TFTC.

448
00:44:37,860 --> 00:44:41,420
If you've made it this far, I imagine you got some value out of the episode.

449
00:44:42,040 --> 00:44:45,800
If so, please share it far and wide with your friends and family.

450
00:44:45,880 --> 00:44:47,220
We're looking to get the word out there.

451
00:44:47,220 --> 00:44:54,260
also wherever you're listening whether that's youtube apple spotify make sure you like and

452
00:44:54,260 --> 00:44:59,660
subscribe to the show and if you can leave a rating on the podcasting platforms that goes a

453
00:44:59,660 --> 00:45:05,780
long way last but not least if you want to get these episodes a day early and ad free make sure

454
00:45:05,780 --> 00:45:12,580
you download the fountain podcasting app and go to fountain.fm to find that five dollars a month

455
00:45:12,580 --> 00:45:18,520
get you every episode a day early ad free helps the show gives you incredible value

456
00:45:18,520 --> 00:45:25,640
so please consider subscribing via fountain as well thank you for your time and until next time
