4 ms·
Safety deposit boxes are cheap. Put your encrypted PK on paper, store copies in 2 or 3 separate boxes. Your password can be stored in your memory. Or it can be
by bufferoverflow 8y ago
Safety deposit boxes are cheap. Put your encrypted PK on paper, store copies in 2 or 3 separate boxes.
Your password can be stored in your memory. Or it can be something like the 100th sentence in your favorite book.
- clarkmoody 8y agoDon't use any portion of any written work as your private key! Brute-force attacks will use every bit of written literature to do this same search. You must use securely-generated random key phrases, or you will lose your coins.
- dsfyu404ed 8y agoNo key is safe from a brute force attack that covers the alphabet of key and the length of the key. What you're describing is a dictionary attack and it trades comprehensiveness for speed. There's many more words than characters in any language. Using words as your alphabet gets you ($WORDS)^N possible passwords of length N instead of 128^N for an ascii alphabet. For humans remembering random words is easier. Choosing a grammatically correct sentence instead of random words is little different in terms of complexity reduction than choosing a word based password (e.g. Password1) instead of random characters. Obviously if the attacker can build a target specific dictionary they'll have a higher probability of success.
- clarkmoody 8y agoIndeed. My caution is against keys that are already in the clear in a written work. Bitcoin is cryptography's biggest bug bounty.
- bufferoverflow 8y agoI said password for the private key, not the private key itself. I store my PKs in KeePass databases with a crazy number of rounds, so each password guess attempt takes 2-3 seconds on a modern CPU. Good luck bruteforcing that.