4 ms·
Two things worth noting here: - Not your keys, not your coins. Never keep in an exchange what you cannot afford to lose. - Governments, especially tyrannical
by kemonocode 5y ago
Two things worth noting here:
- Not your keys, not your coins. Never keep in an exchange what you cannot afford to lose.
- Governments, especially tyrannical regimes that don't even need to pretend to respect human rights, will hamper your attempts at circumventing them at every step.
I wouldn't go so far as to declare the whole endeavor hopeless as some people have done here, only that you must be far more careful when covering your tracks. It's not a turnkey solution, there are few ways to get it right and a myriad ways to get it wrong, it sucks but it is how it is. If it weren't working, then they wouldn't be bothering trying to ban payments in crypto.
- deleted 5y ago[deleted]
- xiphias2 5y agoTaking the keys private doesn't scale long term, as people still have to secure them. I believe the long term solution of secure Bitcoin storage is more companies allowing multi-sig key signing. Unchained capital allows Fidelity to hold another key and you the 3rd, but I don't see why it couldn't be done more generally using PSBTs.
- deleted 5y ago[deleted]
- dumpsterdiver 5y ago> Taking the keys private doesn't scale long term, as people still have to secure them. I believe the long term solution of secure Bitcoin storage is more companies allowing multi-sig key signing. It's a mixed bag, because while multi signature key signing would help mitigate events in which a key is compromised or lost, it would also expand the attack surface. Some might argue that it's easier to obtain a user's login credentials (for instance, by exploiting an XSS on a site storing one of your keys, or by posing as a support agent who "verifies" your security questions) than it would be to trick someone into handing over their private key outright. You do have a valid point though, in the long term it's unclear how well people will manage to secure their keys if they choose to take that burden entirely upon themselves. A natural disaster, for instance, could cause a lot of private keys to be lost. That being said, I would never trust a 3rd party to hold any of my private keys, because at that point they are no longer private.
- xiphias2 5y agoCompanies have protocols where you get an email and have to wait a few days before they send out large amount of money (and that setting can be modified by the user by the same way). I would maybe be comfortable with a 2-of-3 multisig between Switzerland, Singapore and US. I'm already trusting 3rd party to hold my private keys though: it's a 2-of-3 multisig between 3 bank trezors (the banks have no idea what I am storing though, they probably think that it's just gold). It would be easier for a bankrobber to get the gold from the other vaults than to rob multiple specific banks in multiple countries. Anyways you are right in that it's much better to require physical identification for retrieving large amount of money, and you get better privacy by the physical trezors.
- dumpsterdiver 5y agoTo be clear, I never advocated a "trezor" and I wasn't aware of the term before you mentioned it just now. I am only suggesting that you keep your keys close, and trust them with noone.