Lead Core Lightning, Standards Wrangler, Bitcoin Script Restoration ponderer, coder. Full time employed on Free and Open Source Software since 1998. Joyous hacking with others for over 25 years.
Public Key
npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Profile Code
nprofile1qqs0zuj4s6jq9sr2ajqc69rc53d25rwpd3afcjrfm97r2qek69hcuscpp4mhxue69uhkummn9ekx7mqpzpmhxue69uhkummnw3ezuamfdejscc5rc3
Show more details
Published at
2024-06-08T03:44:48Z Event JSON
{
"id": "2a2f9df4a08077b41de1ca2ec3dd7d072ca45729a1f8debdf711e46de1586e6b" ,
"pubkey": "f1725586a402c06aec818d1478a45aaa0dc16c7a9c4869d97c350336d16f8e43" ,
"created_at": 1717818288 ,
"kind": 0 ,
"tags": [
[
"alt",
"User profile for Rusty Russell"
]
],
"content": "{\"name\":\"Rusty Russell\",\"display_name\":\"Rusty Russell\",\"website\":\"https://rusty.ozlabs.org\",\"about\":\"Lead Core Lightning, Standards Wrangler, Bitcoin Script Restoration ponderer, coder. Full time employed on Free and Open Source Software since 1998. Joyous hacking with others for over 25 years.\",\"lud16\":\"npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s@npub.cash\",\"nip05\":\"[email protected] \",\"picture\":\"https://rusty.ozlabs.org/images/Rusty_Russell-lca2011+crop.jpg\"}" ,
"sig": "16ded7f3f6efc75faa92bca1936052a0244e479662f36393857d45acceeca06f47ccdc61e1156b673c7a06ae17ff1804ac8177da28aecb38b1d4dba8e3b7b8ef"
}
Last Notes npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Hi from https://cashu.centurymetadata.org npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I take birthdays seriously! https://npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s.blossom.band/dd4c1dec153d7b2619e2c115b344d4d250ad89832f94f25a7bfd1d38b0dc127a.jpgbirthday npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Time for a Rocky Horror / Muppet Treasure Island double feature! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Don't confuse a 2 week embargo with closed source. They're in a hard place. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Manager of the Lightning Team, she signed the last 5 releases? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell You can also restart with --developer --dev-no-version-checks --subdaemon=openingd:/DNE --subdaemon=dualopend:/DNE This prevents new channels from opening (by telling it to use subdaemons which don't exist: the dev option stops it checking at startup). If you think your node is unlikely to be messed up by existing peers, and you're just worried about new ones. #nevent1q…uk05 npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Calle misread. It says upgrade when the release comes, or go --offline. It absolutely did not recommend "shut down NOW" 😕 npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Was he actually malicious? I disagreed with him, but there is a difference. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Very few builders in this space are actually malicious. But many need to get out and touch grass. Myself not excepted! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Yes, classical C has the problem that operations are low-level, so if you overrun the end of a buffer, instead of a crash report the attacker can make arbitrary commands run. Also, manually deallocating memory can be omitted (oops, program grows over time, crashes) or done twice (also classically tricked into running arbitrary code). Also, the standard routines are minimal, forcing programmers generally to deal with these issues everywhere. CLN has a *lot* of internal infrastructure to avoid code having to do this. Firstly, the tal hierarchical allocator removes most manual deallocating, and all the infrastructure relies on it. Second, all the wire demarshaling routines are generated from spec files, and all come down to two hard-to-misuse routines (note: the bolt11 parsing was hand-coded by me, didn't use this, and had serious bugs!). Finally, we use patterns designed to highlight issues early, including running test cases under Valgrind (a memory debugger) and internal memory leak detection. But as one developer said "It's not coding in C, it's coding in Rusty's C"! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Yet last I heard, libsecp256k1 held up pretty well? On a less vague - posting note, I had Kimi work through CCAN for bugs, resulting in about 100 commits. I'll go through this morning and see how many are C mistakes, but I don't recall many (and yes, I reviewed each one carefully). But it's mostly my code, and I've got a fairly defensive style built over a long career of mistakes. I should probably post about that... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Oh, winning! Pretty good stats on a really cheap die. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Here's something I've been working on along similar lines: https://github.com/rustyrussell/bip39dice Haven't published it yet, since it needs a helper video and some serious analysis (i.e. how biased are normal dice, and how biased is hand rolling) and of course concrete recommendations for the final word fixup. But being able to *verify* that your phrase is random is far better than other approaches, if you're going to roll... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Day 3 of grinding kimi to do a complete CCAN audit (CCAN is the repo of C snippets I maintain, used by many projects including Core Lightning). So far, some minor issues: mainly for weird corner cases not used by any codebase I'm aware of. But many of them, and this is battle-tested code. It's impressive how cheap this is: I'm still under $50 spend, and less than 8 hours of my own time. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell No: if the grid is the entropy it's just a memorized wallet. The point is that the grid is low enough entropy that you can remember it. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I have not found a correlation between developer attitude and brilliance, regretfully. The rise of Free & Open Source Software added a bias, though: developers who played well with others made more progress in the long term. That and the internet made software a social activity. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I don't think burying Coinkite is the right answer, BTW. But reality rarely listens to my opinions! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell No, you got a convincing-looking letter in the mail and upgraded your firmware, coins lost. Oops. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell But it won't stop someone like this who doesn't use it. Perhaps a secure_rng() API which refused to fall back? But that would have to be plumbed though all the Python libs too. And maybe they would have hacked it out anyway, in the hurry to remove GPL code? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Patterns are the enemy of entropy. Because this is harder to evaluate, it looks better at first glance. If you assume people draw contiguous patterns, what is the actual entropy? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I disagree with nvk on several things, but I like his uncompromising approach to hardware and shipping. Testing for weak entropy is hard, this is absolutely a mistake I could have made, and I would also be furious if this lost my funds. I've been trying to come up with a witty name though. Stolecard? Goxbox? "MicroSiphon inside"? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Because it was a fake letter sent to their home address based on the ledger leak and in fact was instructing them to install malware that stole all their coins :( npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Today's side quest: Great Speculations (greatspectations.com). Useful tool for checking source code quotes against a document: I used this in CLN and it improved compliance *and* the spec itself, as well as making it easy to follow spec changes. This is the polished and published version which handles RFCs, BIPS, and any other markdown or other docs. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell What a horrible day. I am haunted by the fear that a normal Bitcoin use can do everything right, only to lose everything because you didn't hand-roll your entropy, or upgraded your firmware because "Ledger" sent you a warning email. 😢 npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell The problem with this is that well-run, boring, positive cash flow companies are really hard to find. All the obvious ones were snarfed up by previous variants of this play. It *sounds* great, until you get to the messy reality that the firms you want don't need you. So you have to find and pitch them. And why would they say yes? Because they're looking for an exit, which is the opposite of what you said you wanted. This is not to say it's impossible, but there's a reasonable case that it's going to be far harder than VCs think, who are used to people approaching them. #nevent1q…77pv npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Apparently the idea that we should be our best online, not our worst, is radically outside the mainstream? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Copyright was important and unassailable until there was Real Hot Money in ignoring it. I'm not *happy* that intellectual property got broken by greed, but TBH I'm pretty happy... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell More like "Bitcoin ALREADY HAS cured cancer, you just don't know about it yet!!!!" npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell At #OsloFF several people asked when Shit Bitcoiners Say would be back, so let me put it on the record: it's hibernating during the bear market. The account serves me as a balance, to keep things grounded. It's not there to kick people when they're down, it's to serve as a reality check. When Bitcoin is a grind it should be offering free hugs or something. When people are extrapolating to infinity and you feel the urge to research low-gravity espresso machines for your inevitable Bitcoin moon-citadel: I'll be back! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Hey @nprofile…6z2t should I be pitching @nprofile…g954 to OpenSats? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I'm back wearing a Pebble watch! I loved the original, and wanted to support the reboot. Let's see how we go after a month... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell This is my new Century Metadata account. I'll try to remember to post CM stuff there, not here! #note1fx9…kelx npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell This is really touching! I loved working on #bitcoinlightning and #CLN over the years, and I leave both in excellent hands. Lightning is going to be so much more than it is now... #nevent1q…f93p npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Official Bitcoin Twitter Self-Worth Chart $70k: your hairline recedes. $60k: gangrene develops. $50k: you lose the ability to make coherent sentences, and all you can say to your panicked loved ones is "Bitcoin is digital energy". $150k: erectile dysfunction vanishes. $250k: your wife returns with the kids, saying she made a terrible mistake. $500k: your long-dead father rises from the grave, tells you that he was wrong and you were right, and he's proud of you. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell So I'm leaving Blockstream at the end of the month, to try to start up Century Metadata. A non -profit to store and serve a small amount of encrypted data for 100 years, for a small one -time payment. Lots of fun problems in doing this, only half of then technical. I'll be talking about it at BTC++ in Vienna, and I'll also be attending the Oslo Freedom Forum just afterwards. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell The main benefit of LLMs is that you don't need to apologize or justify when you clean up their mediocre code. It's a bit like having an insomniac coding intern who really likes to type. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I've been thinking about taking profits from a Sztorc Fork. I wouldn't sell someone a lemon face-to-face, even with full disclosure. Sure, they're adults, but the world is a better place when we care for each other: that is not who I want to be. Do not enable bad things. The anonymity of the marketplace does not absolve this. So, no. I will not encourage it, talk about it, or handle it. And I'll sleep great. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Guess in getting up for 5:30am then. #nevent1q…0790 npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell So, we're debating paying kids pocket money in sats. Since we're talking a few dollars a week, I'm thinking ecash, using https://cashu.centurymetadata.org/ But what client? They have Android devices... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell https://youtu.be/iDzV_jESwGA Indeed. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I wish! No, it rolls back the database, deletes the gossip store if the format has changed, and checks of you've used any new features which would prevent downgrade. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell We pushed it a bit on this one: There are some clients who may have trouble staying connected to you: LNDK nodes and some people who are running an older git version of LND. You can set message-padding=false if this happens. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell The idea of an activation challenge is interesting. But my preferred form would be an on-chain reward. A tx which uses its first input's txid to generate the puzzle NUMS, so you can't just copy it. Not sure how to generate such a challenge, maybe GSR, OP_TX plus cleverness... This would start a month-long (4032 block) countdown to disabling vulnerable spend paths, as a final shot across the bow. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Yes. #nevent1q…vary npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I've been through tech hype cycles before. They always have a grain of truth in them (otherwise they're trivially refuted) but they don't always work out. I have been through three VR waves, for example. I can't tell where Quantum Computing will land, though it has all the signs of needing a few more decades of occasional hype cycles. But I *can* tell that all the proposed mitigating signature schemes for Bitcoin suck hard: they're technically impressive because they're 10x better than I expected, but they're still 10x worse than what we have now. This means two things: I applaud and support the continuing research. And I won't support a soft fork any new cryptographic schemes until the someone demonstrates an extant QC that can factor faster than a classical one. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Americans trying to get back to the moon and missed. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Wow, that's some lunch with the mayor! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell No, it's all agentic payments! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I keep hearing about all the billions left on the sidelines, which will come rushing into Bitcoin when some legislative or regulatory event occurs. Here's some history: - Bitcoin futures ETFs. October 2021, price $61k - Bitcoin spot ETFs. January 2024, price $42k - March 2026, price $70k Now, maybe it's still coming, but at this point you might want to start doubting this narrative. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Hmm, stuck in "processing". npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Actually, I'm not sure how. cashu.me doesn't seem to give me an option. I see my node made a 5000 sat bolt12 outgoing psyment about 6 hours ago though... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Let me try... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Now I serve a web page at that URL. Probably presents too much info. @nprofile…xnfk might have suggestions for what I should put here? #nevent1q…eekl npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Fired up a cashu mint today: should exercise my CLN node a bit more! https://cashu.centurymetadata.org npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Token bucket filter for the win: most occasional posters are not *regular*. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Finally read BIP-54 (mirror at https://bips.dev/54/) and it is straightforward,minimal and thorough. At this point I can endorse it as a good idea and worth doing. There's no rush, but I am looking forward to activation. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Here are two of my favorites: Vaults, where your coins can only be spent with a delay, so if you see your coins move and it wasn't you, you can force them to emergency backup address instead. Lightning and other layer 2 protocols get simpler and more efficient. In the case of Ark, it sheds some cases where you need to trust the provider. These ideas came up long after the script stuff was disabled. There are certainly more npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell https://json5.org/ I *want* JSON5 to take over the world because it allows trailing commas. But I have to accept that most people are just excited because it sounds like a boy band. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell https://github.com/bitcoin/bips/pull/2118 Finally, the PR to assign BIP numbers to the first two BIPs of the "script restoration quartet". Here's the corresponding bitcoin-dev the mailing list post: Hi all, I've submitted a PR to the BIPs repo to merge the first two drafts of the previously posted[1] "A Bitcoin Scripting Proposal BIP Quartet": https://github.com/bitcoin/bips/pull/2118 The only substantive change since the last discussion is that the costs have increased for some operations (hashing and copying bytes), as a result of benchmarking on a wider array of machines[2]. This follows our conservative approach to make the worst-case validation times no worse than they are presently, on any viable hardware. The remaining two BIPs (OP_TX, and new opcodes) are not submitted: they are mainly useful to provide a roadmap what functional gaps remain after the script extensions, and do not have full implementations. Cheers! Rusty & Julian. [1] https://groups.google.com/g/bitcoindev/c/GisTcPb8Jco/m/8znWcWwKAQAJ [2] https://github.com/jmoik/varopsData npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Kick the can down the road? I cannot see the appeal from any direction... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell You are minmaxing again. Enjoy the scenery and sense of wonder! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell https://rusty-lightning.medium.com/the-three-economic-eras-of-bitcoin-d43bf0cf058a This is still the best piece I ever wrote on Bitcoin. It occasionally gets referenced somewhere, and I reread it. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell To check the signature, you hash the transaction. So the only cost that OP_RETURN is doing is the cost to download and hash it. If it's data in the annex you don't even need fi hash it, just download it. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell You only have to download and hash: you don't have to check extra signatures (our most expensive operation) or put them in the UTXO set (our most constrained memory resource). npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell You will not be at peace until you understand the truth: every non-coinbase bitcoin transaction which does not eventually send funds to me is spam. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell So, OP_RETURN is fine, as is annex data which don't increase validation burden? And cutting off OP_RETURN and driving those uses to fake pubkeys, which does increase future validation costs, is a threat? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell It adds an entire transaction! Every time it does that, it uses up farmore space than an 80-byte OP_RETURN. So your conclusion is that it's not spam if it looks like a normal transaction to you? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell OTS transactions only exist to put non-financial data in the Bitcoin blockchain. Is that ok? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Indeed. Lightning commitment transactions stash the commitment number in the nSequence and nLocktime. Is that spam? OpenTimestamps uses full transactions to timestamp data, is that spam? Samurai (IIRC) had a method of obscured payment addresses which required an initial seed tx. Was that spam? You can encode data in the key used when you use a taproot script spend path. Is that spam? (Can you tell?) npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell None of those celebrating her departure are Bitcoiners. Because clearly they neither understand or like Bitcoin. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Reading comments on Gloria's departure from people who have never contributed anything is stepping in an enraging sticky fecal mess. The only appropriate response: keep building, keep unashamedly celebrating those who do. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I have been having way too much fun reading moltbook.com As one wit on HN (I think) pointed out, these AIs are trained on Reddit posts, so they have exactly the same style. My wife keeps looking at me funny as I LOL at some breathless word salad... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Damn, there was a proposal for BOLT spec changes to enable fixed-size messages, and now I have to implement it to show it's unnecessary... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell https://rusty.ozlabs.org/2011/05/19/if-you-didnt-run-code-written-by-assholes-your-machine-wouldnt-boot.html I wrote this over 15 years ago, and it still rings true: separate the art from the artist. It's a key stabilizing principle for me when navigating Bitcoin developers. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell 1. No, I'm not reading your article on quantum. 2. Yes, all choices are bad. That's what "breaking" means. 3. I'm glad smart people are thinking about technical mitigations. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell BROKEN: Full KYC. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell @nprofile…xxx2 recently posted on X about the danger of "store and forget" for Bitcoin over decades. Unfortunately he's right. Originally I stored my raw private keys and UTXOs (on paper, care taken) figuring that was standard. Then bitcoin core stopped supporting them! Other wallets tend only to support them for sweeping, and I wonder how long. If I were storing funds today I would use BIP39. BIP93 is cool and more general, but not widely supported, and I don't know what support will look like in a decade. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I hate price talk, but if you're going to do it, please understand that "market cap" is a very rough *ceiling* on current value. It's neither the amount of money which has gone in, nor the amount of money which can come out. So the order of magnitude is useful to compare against other assets. But abusing it in terms of profits and losses is a category error, and I assume done mainly because it's so easy to measure. Grump over. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Don't suggest a developer resign unless you're the one who will shoulder the load. And if any bitcoin developer is thinking of stepping down over the current drama, *please * reach out to me: I've been a FOSS dev full time for over 25 years and I've been there! I'm not going to judge, but I may have a useful perspective. ❤️ npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I love BIP 93, with its ability to store any secrets with super-high redundancy and natively handle multiple shares by hand. But I also love BIP 39 for the simplicity of 12 words, and the universality of the standard. I want a word scheme for BIP 93. It would be 20-23 words(depending on what scheme is used), but highly redundant. You could recover with 3 or 4 unknown words. Ideally the word list would avoid near-miss words, and be distinct from BIP-39 enough that it would likely be distinguishable, rather than relying on the strange number of words. Should this exist? npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I watched the video of @npub1cev…etlq's Bitcoin-Lisp-Script talk (https://brink.dev/blog/2024/12/19/eng-call-aj-towns-bll/). Summary: 1. Lisp a the classic alternative to Forth for embedded use, so makes sense for Bitcoin Script. 2. Iteration is definitely a super power. 3. Definitely worthy of further research. My main concern is that it requires much more broadly-defined limits. The varops work does a very limited subset of what is needed in general, *because* we operate within a 4MB max opcode limit already. varops *only* has to extend it so that large data doesn't make things worse, and we get to ignore anything which isn't proportional to data being operated on, figuring that's already possible. An approach with iteration has to worry about more than that, requiring a general system of CPU consumption limits. That's not impossible, but I have *not* done that. For example, OP_DUP3 of three empty stack operations costs 0 varops. If you could do billions of these, this assumption that we can ignore those stack operations would be invalid. The good news is that I am tending into that area with my OP_MULTI proposal. Prior to this, nothing operates on more than 3 stack entries, so ignore the overhead of stack operations (OP_ROLL is the exception, but in practice it's really fast, and still limited to moving 998 entries). With OP_MULTI, this needs to be taken into account, and if it can cause significant time to be spent on stack operations, the varops model will have to be extended. However, OP_MULTI is still very much limited to the stack size. To be fair, I'm considering increasing that from 1000 to 32768, because it's reasonable to have almost that many outputs (P2WPKH), so I might be forced to extend the varops model to cost that appropriately. Now I need to go read AJ's Python code, since I have other questions about the exact nature of these limits (does space include overhead? 0 byte allocations are not free!). So, if you're interested in extending script, I believe you should fairly consider this. I would like it to advance to a proper BIP, of course, so we could get more of an apples-to-apples comparison, and that's a lot of work! Side note: everyone working on Bitcoin Script replacements is smarter than me. It's intimidating! 💜 npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell After several years of FOMO, I finally attended HRF's #OsloFreedomForum. I took a friend who's political but not Bitcoiner, so I had the experience of seeing it through someone else's eyes, as well as my own. Obviously there's a lot to unpack: talking face-to-face with activists who are working in real danger is confronting in itself, and hearing their experiences fresh and recent is an emotional and impactful experience. I was surprised, however, at the large number of Bitcoiners at the conference: it's not a Bitcoin conference, but the HRF (particularly @npub1trr…hdpu) has been courting bitcoiners for technical assistance (and, presumably, donations) for several years now and it has resulted in a fascinating intersection. Those present are builders, not (just?) talkers. My non-bitcoiner friend noted the remarkable humility of those present: an insightful comment. Of all the discussions I had, the one which haunts me most is a conversation with Peter McCormack (ex- WBD, now rejuvinating his home town and trying to raise awareness of UK's pressing misgovernance issues). To paraphrase: "Where are the Bitcoiners improving the world? Wasn't that what this was about?". In a context of three days' exposure to people who are dedicating their lives to something much bigger than software, this question really affected me. I was expecting to leave the conference with a list of software priorities, and I did. But I still feel it's inadaquate, and so I'm now pondering the question: "what else should I be doing?". npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Capitalism is good and noble and drives competition for the betterment of everyone! It's only the unholy fiat which drives people to lower quality or shrinkflate! They would never think to increase profits that way otherwise! Seriously, if you're making these arguments and nobody's pushing back, they're either not listening or you're in a bubble. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I don't identify as a #Bitcoiner. I do identify as a Free Software developer. From my perspective, Bitcoin is just the project that needs the most development from my skills right now (or, less charitably, where I can have the most fun!). But if you think of me as a #Bitcoiner you're going to be terribly disappointed with my non-traditional RL friends, oddball political views and weird hobbies. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell #Bitcoin price predictions and stupid people attract. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Anyone set up NWC on Core Lightning? I don't really want to have to read all the NIPs and implement YA nostr client! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell There are many arguments why it won't happen, but they're at a disadvantage because it *did* happen to Ethereum apparently. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell FFS. Someone says someone said Trump said he holds a lot of Bitcoin. There is no signal in that noise. None. https://image.nostr.build/99a61c89cffe0b0b9a3eed3c513752d15fdb58c8393f3a4aa86959b25055e0f4.jpg npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Wait, you haven't seen The Princess Bride? (Now I'm trying to figure out the easiest way to stream this while on vacation...) npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I am a little surprised by those buying into the idea that Trump will lead a deficit-reducing administration. I expect conflict, chaos and massive falling out, with the result being business as usual. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I mainly end up hiring workaholics. This is a consequence of seeking passionate, smart people who love their work. So as a manager I mainly find myself telling them to take more leave and asking pointed questions if I receive an email from them far outside hours in their TZ. But it also means I model the behavior I want, which helps me regulate my own hours. I have youngish kids, and my wife has her own career, so I try to stick to my weekly work hours. And I broadcast that to my team. I want to work with these people for a decade, so it's a marathon not a sprint. npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I, too, am doing conference-presentation-driven development! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Sorry! Gotta live some life tonight :) npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell FIFO Sydney for cheatcode.co.uk panel: really disappointed I couldn't do the whole thing. Hope this gave people a taste of Bitcoin developer thinking, at least! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell Your temperature is wrong? 220°C is very hot: https://image.nostr.build/b2f408867ec3998aafeab5be11d33c526619b6ac4d9893b0b0488e8884739c98.jpg npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell I have mid/late twenties friends who live on them. It's weird to me, but definitely a demographic... npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell BOLT 12 is merged into the spec To applause at the Lightning Spec Summit dinner! ❤️ npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell First up, I want to recognize that this is an uncomfortable topic! Bitcoin is inevitably changing towards user-pays, and that's not all positive. But facts we don't like are still facts: can't engineer a solution if we can't think about the problems. There are three kinds of bitcoiners. A. Those who can afford any fee. B. Those who can afford a UTXO, but not often. C. Those who can't afford a UTXO. Nobody worries about the A group (and in the early days, that was everyone). Obviously Lightning (my area!) caters to the B group, and we want it to be as large as possible. To do this we can (1) make lightning as resiliant as we can so onchain spends are rare, (2) make bitcoin as efficient as possible so we can cram as much as we can into what we have. (1) Making lightning more resilient and reliable is engineering. Lots of people working on this, even before we get soft-forks which could help further. (2) More efficiency has two benefits: obviously if your own onchain spends are 20% smaller, that's 20% cheaper. But if *everyone's* onchain spends are 20% smaller, that means fees are lower *for everyone* too (and it's non-linear). So we really care about all Bitcoin usage! Some things are obvious wins: Taproot so you can avoid even putting the script onchain in many cases, FROST so you can cram your 2 of 3 or other scheme into a single key and signature. We know we want to get more aggressive with sharing one signature across multiple inputs (Cross Input Signature Aggregation), but that needs a lot more research, and a soft-fork. But even with all these, the math is clear: some people, even if you somehow gave them their wealth in a UTXO, it couldn't afford its own fees to spend. The C group is real. Spoiler alert: we don't have an answer for this! But let's look at some approaches people have tried. Firstly, there are attempts to move these people into the B group: give them long enough that maybe fees will reach a point they can afford. This seems unlikely to me: 1. As fees increase everyone will start doing the work to take advantage of low fee times, and that itself means that low-fee times won't be so low. 2. These schemes tend to increase onchain footprints, so they need fees to drop a lot to overcome that (typical is 2x the transaction size, so you need fees to halve to gain anything). 3. If you really can't afford the fee, you probably also can't afford to wait. 4. You still haven't actually dealt with those who really, really can't afford the fees. Ever. Another suggestion is that someone (e.g. a lightning service provider) will lock up funds which would cover fees, in case something goes wrong. This doesn't work economically, because nobody is paying $100 for a $5 user (not at scale), but it doesn't even work mathematically: the reason some people will have small UTXOs is because there are not enough sats for 10 billion people with any realistic distribution. There are two basic approaches left: 1. Group people, so they fall into the B category (i.e. onchain tx is possible, but expensive). 2. Trust someone, but rely on incentives. 1. Grouping people is possible, but they need to work together if somenthing goes wrong. So grouping inside a community is probably better than grouping with randos. For example, there are various tree-of-transaction schemes where you go onchain only if the coordinator fails/goes rogue, and how much it costs you depends on whether anyone near you in the tree pays to get themselves out. These are basically free if nothing goes wrong (one UTXO required for thousands of users!). But this is subject to ghettoization, where the coordinator makes sure all the C people are grouped together, knowing none of them can afford the transactions they need to get their funds back. It's particularly bad because the coordinator can insert its own fake "whales" to make it look like it's not ghettoized. You can play with incentives here, too: more research needed. The details matter! 2. Relying on incentives. As a simple example, lightning-connected e-cash mints. They can't rug individuals very easily, they have to rug everyone together (or go fractional and rug the last ones to exit). Maybe with enough anonymity and reputation, these would be Good Enough. More ambitious would be a single UTXO held for multiple people by a coordinator. Can we make it so that if a coordinator is dishonest, you can force them to burn your funds? Maybe burn more than your funds (ie. a bond)? Won't get your money, but it aligns incentives so they're not motivated to rug you. The details here really matter! There's a cute scheme which has been proposed where the coordinator pays a temporary bond, and asserts that they actually have everyone's signature to transfer the funds. If nobody challenges within a week, they get the bond back and the funds move. If someone challenges, all the signatures are put onchain, and if they're not all valid, the bond gets half-burned and half-given to the (successful) challenger. This is hard to make work, though. Someone needs to get the money to challenge (hard if you don't have the money in the first place, plus it's hard to prove to someone you *didn't* sign something!), and then make sure nobody gets the challenge bond before them (in particular, a dishonest coordinator, seeing the game is up, completes the successful challenge *themselves* and gets half their bond back), and make sure someone can't grief and delay the settlement indefinitely or bankrupt the coordinator. More research needed, here, too. Summary A longer post than I had expected to write. And it's buried in the middle of a thread nobody will read. (I do this sometimes. I suck at marketing I guess!) Sub-fee bitcoin amounts will have tradeoffs, involving trusting someone who has more money than you (at least, in someone's competence, even if their *financial* incentives can be made to match yours). This is difficult to build well, and not a very exciting thing to build today, so it hasn't really happened (custodial things are much, much easier!). This is also a key reason I believe we need to make Bitcoin more expressive: if we can do *more* with our own UTXOs, we can build better solutions. And by "we" I mean "someone smarter than me" of course! Feedback welcome! npub179e9tp4yqtqx4myp35283fz64gxuzmr6n3yxnktux5pnd5t03eps0elz4s Rusty Russell #dev #CLN I've spent the last few workdays completely reworking our onion message code. This was scattered in various places and I wanted to unify it, and also written several years ago and I'd forgotten how the protocol actually works! onion messages are *double* encrypted; this is the main source of confusion! At the high layer, they're a series of nested encrypted calls ("onionmsg_tlv" in the BOLT 4 spec), so each recipient decrypts and hands it on: this is exactly the same as we use for payment information. But inside that is *another* encrypted blob (onionmsg_tlv.encrypted_recipient_data), which requires a tweak which was handed to you alongside the onion, for you to decrypt (into an "encrypted_data_tlv"). Inside that is all the information about where to send next, any restrictions, and allows you to calculate the *next* tweak to hand on (it can also override the next tweak). The double encryption is necessary because there are *three* actors here: Alice wants Bob to send her a message, without revealing her identity. So she gives Bob a "blinded path" which goes via Charlie: this path contains Charlie's pubkey (where to start the path), a blinding tweak, and two encrypted blobs for Alice to put into each layer of the onion message. The first an encrypted blob which Charlie can read, which contains her pubkey so he knows where to send it next. The second is her own, and contains a secret specific to the purpose of this message, so Bob can't play games trying to use this blinded path for anything else ("hey, are you the same node as this previous payment?") or use a different blinded path for this purpose. She can also add dummy hops (we don't yet), which she will simply absorb, to obscure the path length from Bob. You can add padding to make the hops indistinguishable (we don't yet). Bob puts the actual stuff he wants to send Alice into the final onion call (often including his own blinded reply path!), along with the encrypted blob. Importantly, even if Bob were sending a message *not through a blinded path* he would use the same double-encrypted format: that's so Charlie can't tell whether a blinded path is being used or not, even though it's slightly less efficient. Crypto is cheap these days, too. Now, if Alice gives Bob a blinded path to Charlie and Charlie is Bob's peer, he can simply send the onion and the first blinding tweak to Charlie. But if Alice needs to send the message via Dave to Charlie, she needs to prepend a step. That's not quite possible, naively, because blinding tweaks are generated *forwards*, and she needs Charlie to get the right blinding tweak from Dave, and Alice has no way of making that happen. So inside Dave's encrypted blob, she uses next_blinding_override to tell Dave to hand that blinding override to Charlie instead of the normal one. I just implemented this for Core Lightning (previously we would simply connect to the first node, which is privacy-compromising and should only be done as a last resort). These blinded paths have some nice properties: you can't use part of them (you don't know the blinding factor except for the first one, so you can't start in the middle, and you can't replace any data), you need to use all of them. They can contain timelimits to avoid easy probing, too: a classic measure would be to see if the path fails when a given node is down, but that takes time. The spec insists all errors within the blinded path are the same, and originate from the entry: this loses some analytical power on failure, but makes probing harder. The entry point is supposed to add a random delay (we don't yet!). There may still be implementation differences, but they're hard for Bob to probe (and Alice doesn't need to, as she set up the path).