4 ms·
Shamir is one of the suggested ways to restore crypto in case of death with more decentralized trust. You select 20 friends and give them each one of the keys,
by thinkloop 6y ago
Shamir is one of the suggested ways to restore crypto in case of death with more decentralized trust. You select 20 friends and give them each one of the keys, then at your funeral 10 or more of them come together to unlock your wallet and execute your will. But it has a big problem: rot.
It needs to be accompanied by a system that ensures everything is still in tact. The system would ping every key holder every X months and have them prove they are still in possession of their key. If a problem arises the wallet owner is alerted to deal with it. Otherwise she gets an all clear report.
The annoying thing tho is now there is a centralized 3rd-party database of all your key holders. Part of the security is nobody knowing who's in on it. Imagine a wallet with $100M. That database starts becoming valuable. So the service would have to be zero-knowledge or hosted, but now you're hosting stuff, and not just any stuff, the most valuable stuff, requiring top security.
- Canada 6y agoThe other problem is that the shares must be combined to recover the secret and doing that safely is hard. It's not a problem if the use case is say, protecting the recovery key for my laptop by giving shares to friends. But in the case of bitcoin, who's going to be allowed to see the resulting secret? Might result in a race to steal the coins. So then there has to be more than 1 group of SSS, with each one getting key for a multisig wallet... or some other carefully executed key ceremony... and the more of such things that are required the more fragile the scheme becomes in practice.
- thinkloop 6y agoI envisioned the keys coming together at the notary's along with the rest of the estate, with a transaction immediately executed to the final recipient. This is a semi-trusted setup after-all. Also the final recipient would likely be one of the key holders present at the ceremony.
- nope96 6y agoI have usually seen multisig as the recommended way, not Shamir. One Shamir vs multisig article : https://medium.com/clavestone/bitcoin-multisig-vs-shamirs-secret-sharing-scheme-ea83a888f033 https://medium.com/clavestone/bitcoin-multisig-vs-shamirs-se...
- e79 6y ago[removed]
- thinkloop 6y agoThe only thing I don't like about that is that it is dependent on the network. Some cryptos don't have multi-sig for example. It's a full system, you have to be aware of protocol changes and such - Shamir is straight math and works on any type of key independent of the system. Trade-offs as usual I guess.
- neokantian 6y agoThe problem with SSS as an alternative to multi-sig is that the dealer (the person drawing the polynomial to distribute the secret shares) will also know the secret. Hence, this dealer can leak the secret or abuse it. If you want dealer-free 2of3 secret sharing you need to use Diffie-Hellman-style shared secret sharing like implemented in Monero: https://hackernoon.com/monero-multisignatures-explained-46b247b098a7 https://hackernoon.com/monero-multisignatures-explained-46b2... Therefore, I disagree with the article that SSS would be a legitimate alternative to bitcoin multi-sig. By the way, if SSS really were an alternative to multi-sig, then Monero would have simply implemented SSS and not a (more elaborate) Diffie-Hellman style solution for secret sharing in Monero multi-sig.
- ShorsHammer 6y agoTimelocked multi-sig is another alternative in some systems. As time goes on the number of signatures required goes down, this setup can be reset every X blocks as needed. Provides additional security against key loss or malevolent actors at the cost of having to wait it out when such things occur.