13 ms·
I kept my funds on Binance for a while, for convenience's sake. However, the old rule applies: not your keys, not your crypto. Keeping anything on an exchange,
by throwaway77384 5y ago
I kept my funds on Binance for a while, for convenience's sake. However, the old rule applies: not your keys, not your crypto.
Keeping anything on an exchange, for the time being, is just too risky. This is another example of it. Governments are still trying to figure out how to regulate crypto, ever shifting the amount of hurdles between crypto and the world of fiat.
I'd advise to pull funds if possible. I've recently done so with mine.
Of course that means my keys / wallets are now my responsibility, along with ensuring that I have appropriate backups in place etc.
- rchaud 5y agoIs there an ELI5 guide to keeping coins secure when they're off-exchange? I heard terms like 'cold wallet', 'cold storage', but surely there's work that goes into creating a secure USB stick?
- mrgordon 5y agoIn the extreme case people will set up a paper wallet using a computer that’s disconnected from the internet. Once they have the keys, they can typically keep them non-digitally and transfer coins to that address as safe cold storage
- knownjorbist 5y agoConsider a hardware wallet like Ledger or Trezor, both are pretty easy to use and have extensive documentation. I'm sure there are OSS/hardware solutions you can roll yourself, too.
- rawtxapp 5y agoYou can buy something like Ledger Nano which is a hardware wallet. Essentially, the private keys never leave the device, you can instead just sign messages directly with it. You can also have normal software wallets (don't recommend it for larger amounts) or paper wallets.
- jasdine817 5y agoI just used a tool called BIP39 generator on and offline machine which you can feed entropy and it will generate a bitcoin private key. then sent funds to that address. Then just keep those details safe.
- tonfa 5y agoHow do you handle giving access to your keys to your next of kin?
- deleted 5y ago[deleted]
- puranjay 5y agoImportant question - I hope OP can answer. Too many people I know haven’t instructed their dependents how to access their crypto.
- Paradigma11 5y agoAnd how do you prevent access for your next of kin if there is a breakup/fallout?
- rand49an 5y agoJust let them know where those details are and how to access them if they need to.
- whoisjohnkid 5y agoyou can use multi sig wallets. Which are synonymous to Shamir’s Secret Sharing Algo; tldr you can generate say 5 keys and you need 3 of the 5 to unlock. As for if you die … you could use one of those services that will send an email out to your significant others if you don’t log in for X amount of time.
- lmm 5y ago> As for if you die … you could use one of those services that will send an email out to your significant others if you don’t log in for X amount of time. And put your bitcoin private key in there? Surely whoever runs those services would take all your money.
- eingaeKaiy8ujie 5y agoUse a separate computer with a minimal Linux system (maybe even without GUI) and only open-source software to manage your crypto. Your key should be password-protected. Make multiple backups of the key and remember your password. You can also write your password down on paper and hide it somewhere.
- SkyMarshal 5y agoAlso a good idea to use ECC Memory with the ZFS filesystem. That combination can correct any single-bit error, and detect and warn about any double-bit error, significantly reducing the chance of losing data to bitrot. And if you’re backing up your keys on USB drives, use high-endurance SLC NAND industrial drives. They provide the highest reliability and endurance available. https://www.embeddedarm.com/blog/slc-nand-secrets-exposed/ https://www.embeddedarm.com/blog/slc-nand-secrets-exposed/
- Grazester 5y ago"There's nothing special about ZFS that requires/encourages the use of ECC RAM more so than any other filesystem."-Matthew Ahrens
- SkyMarshal 5y agoHis full quote, from the actual source (2003): "There's nothing special about ZFS that requires/encourages the use of ECC RAM more so than any other filesystem. If you use UFS, EXT, NTFS, btrfs, etc without ECC RAM, you are just as much at risk as if you used ZFS without ECC RAM. Actually, ZFS can mitigate this risk to some degree if you enable the unsupported ZFS_DEBUG_MODIFY flag (zfs_flags=0x10). This will checksum the data while at rest in memory, and verify it before writing to disk, thus reducing the window of vulnerability from a memory error. I would simply say: if you love your data, use ECC RAM. Additionally, use a filesystem that checksums your data, such as ZFS." https://arstechnica.com/civis/viewtopic.php?f=2&t=1235679&p=26303271#p26303271 https://arstechnica.com/civis/viewtopic.php?f=2&t=1235679&p=...
- Geee 5y agoUse a hardware wallet to securely generate keys and sign transactions. Hardware wallet is meant for secure use of cryptocurrency, but it is not optimal for long term storage. It's important to buy devices only from trusted vendors, and to make sure they're not been tampered with (never buy them from a third party). For long term storage, you need indestructible and physically secured backup of your keys. Basically, you just need to write down the 12 or 24 seed words generated by your hardware wallet and try to keep the words safe from destruction and theft. It's recommended to use a indestructible material such as steel for these, and then store or hide them safely. For more advanced security, seed words can be split in multiple parts using the SLIP39 seed format. For hardware wallets, e.g.: - https://coldcardwallet.com https://coldcardwallet.com - https://trezor.io https://trezor.io - https://www.ledger.com https://www.ledger.com For long term storage, e.g.: - https://cryptosteel.com https://cryptosteel.com - https://cryptotag.io/ https://cryptotag.io/ - http://bitcoinseedbackup.com http://bitcoinseedbackup.com
- tomp 5y ago> Basically, you just need to write down the 12 or 24 seed words generated by your hardware wallet Why is that in any way more secure than writing down the private key itself? (inb4 "need to find both the hardware and the written seed words" that's equivalent to writing down the private key and then cutting the paper in half)
- rawtxapp 5y agoMuch easier to remember and to transcribe compared to writing down a string that looks like random garbage.
- tomp 5y agohow much BTC are you willing to bet that you'll remember 24 randomly generated seed words? probably not much.. that's why parent was advocating "you just need to *write down* the 12 or 24 seed words generated by your hardware wallet"
- pjc50 5y agoNote that you can secure the coins but not the purchasing power of the coins. 10k bitcoins may be worth a billion dollars or they may be worth a pizza in ten years time.
- onethingatatime 5y agoTo me this is the crux problem impeding crypto. Read all of these solutions: will any of my non-techie friends do those things? No.
- chirau 5y agoIs Coinbase also a case of not your keys, not your crypto? What would be the best way then to have your keys and your crypto? I never really understood the whole crypto storage stuff and how to approach it.
- encryptluks2 5y agoYes absolutely. Coinbase has terrible customer service, often ignoring support requests completely until you go onto social media and try to get their attention publicly before they'll even give you a response. I don't think there is necessarily a "best" way to have your keys and crypto, but usually depending on the crypto you use they usually have an official wallet that you can use where you'd be responsible for the key(s). This means that you act like your own bank though, so if you lose your private key you also lose your crypto. Therefore it is important to use utmost security, privacy and safety when displaying and saving your key. A lot of people swear by hardware wallets like Ledger, and I think those are probably the best options for people that don't know a lot about security and crypto or possible even those that do.
- PaywallBuster 5y agoyep, takes them weeks/months to reply to my email about deposit issues. I guess they don't want my money
- neodon 5y agoYea they are terrible. They told me based on my state ID that I scanned and uploaded that my name was "wrong" -- i.e. if I'm "John L Smith III" they basically said my name is really "Smith Iii L John" and refused to fix it, effectively nuking my account because it didn't match my real (wrong?) name. Oh and it took them over a month to respond.
- raziel2701 5y agoCoinbase, a nasdaq listed company, handles customer support through its subreddit. What's more, a few weeks back a customer got scammed through coinbase's subreddit when his support request was answered by another user impersonating coinbase customer support, instructing the customer to move their coins to a wallet number they gave them in order to solve the issue. The customer lost $75k and there was nothing coinbase could do other than "sorry for your loss". Here's the thread: https://www.reddit.com/r/CoinBase/comments/nhug9u/75000_just_disappeared_from_my_coinbase_wallet/ https://www.reddit.com/r/CoinBase/comments/nhug9u/75000_just...
- grey-area 5y agoDoesn’t matter what you do with your cryptocurrency, the value can easily evaporate because of the actions of others, including binance and those who use it and other dodgy exchanges which make up the vast majority of crypto ‘transactions’. What happens when you want to sell it for fiat you can actually use and nobody wants to buy? So many people pouring money into this space have never seen a bear market or a bank run.
- spottybanana 5y agoBitcoin isn't that new thing any more, to me it looks like fiat holders have seen too many bitcoin holders gain significant value. Yes, there are also those that lose their BTC for whatever reason but to me it seems to be quite a minority compared to those who actually have made good dough just holding BTC. To the tune of having retired on their stash.
- grey-area 5y agoIf you cashed out to fiat and retired on your stash in this last bubble you’re doing great, though that is at the expense of millions of retail bag holders who bought your cryptocurrency hoping they’d get rich too. If you didn’t cash out already and are taking your coins offline etc, you’re the bag holder.
- reidjs 5y agoThis assumes the USD stays dominant indefinitely, right?
- WalterSear 5y agoIt assumes that the fraudulent stablecoin created by Binance, and involved in the vast majority of trades, (more 70%, a few days ago) unwinds. https://crypto-anonymous-2021.medium.com/the-bit-short-inside-cryptos-doomsday-machine-f8dcf78a64d3 https://crypto-anonymous-2021.medium.com/the-bit-short-insid... https://bitfinexed.medium.com/tether-is-setting-a-new-standard-for-transparency-that-is-untethered-from-facts-deec42c473bb https://bitfinexed.medium.com/tether-is-setting-a-new-standa... USDC (the second largest stablecoin), isn't appreciably better.
- dheera 5y agoI don't know about that. For people like you and me that are likely to be familiar with good infosec practices, run open source OSes and only open source software, with no possibility of spyware or ransomware, have offline backups and offsite backups, sure, this advice is fine. For most people though, I feel like exchanges are safer from the more common threats: viruses, ransomware, failed hard drives, fire, floods, "gimme-your-laptop" gunpoint, ... They ironically also make your crypto slightly more anomymized since you aren't always spending out of the same wallet address so when you transfer crypto to someone, they don't automatically know your crypto net worth. I wouldn't trust Binance though. I moved all my funds off Binance for one reason -- their UI (especially authentication workflow) is super buggy, and that makes me extremely not confident that their backend isn't equally buggy. To top that, when I tried to report bugs to them they wanted my national ID to even engage in conversation, instead of fixing the bugs. Fuck that. Fix bugs first and only then will I trust you with my ID. Kraken, Bittrex, Coinbase Pro have solid UIs and give me more confidence in the quality of their engineering.
- pedalpete 5y agoHow about simply losing your hardware wallet? That's what scares me. If I had enough crypto, I'd probably get a hardware wallet and store it in a safe deposit box, but then I'm going to lose that key. I wonder if there is an opportunity for smart contracts around insurance for the exchanges...a bit meta...
- dheera 5y agoSounds hard, because it would be hard to prove that you lost a key. You could always pretend you lost it. But if the blockchain supports actually invalidating those coins and transferring them to a new wallet via e.g. 3 trusted friends with pre-pregrammed wallets that sign and verify your new wallet, maybe it could work.
- earnesti 5y agoIf you are going to involve more people, just use multisig.
- esotericimpl 5y agoThis entire thread explaining how to properly "secure" your crypto is a great example of how crypto will not go main stream until these problems are solved for the layman. The fact that the top comment says "not your keys, not your crypto" shows a fundamental disconnect between hacker news and the general public. Until crypto is centralized and utilized more like a utility will the masses ever move significant amounts of their wealth to the "blockchain".
- KMnO4 5y agoAs an early Bitcoin adopter who was robbed of a house worth of coins by an exchange (Quadriga), I can’t stress this enough.
- hervature 5y agoI know it is tempting to compare the current price when estimating losses. But really, you cannot do that. I had 2.5M dogecoin that was also stolen. But I don't use the peak valuation (~$1.25M) or the current price (~$0.63M) because that implies I would have singled out the peak or held until now. I really only lost my buy in ~$1,500. It makes for a good story to lose a house, but it is better for your sanity to base your losses in actual line items.
- IgorPartola 5y agoThis. If in 2012 you bought a pizza with 1 BTC and now feel silly, don’t. You also bought pizzas for $20 which you could instead have converted to BTC and held until now had you only had a working crystal ball.
- koolba 5y ago> You also bought pizzas for $20 which you could instead have converted to BTC and held until now had you only had a working crystal ball. My favorite spin on this is computing the present value of buying AMZN instead of whatever I was ordering from Amazon.
- enos_feedler 5y agoIs there a script for this? :)
- arp242 5y agoThis is kind of the emotional mechanism behind a lot of crypto investment. It's not intentional, and it's kind of sneaky, but with the strong fluctuations and chance of "hitting it big" there's always the "what if..." feeling. As someone who doesn't care much for crypto (in its current form anyway) and was never involved in it at all, even I have this to some degree as I was aware of it very early on (when it was still interesting, instead of what it's become now). This is probably a big reason why there are so many "amateur" investors compared to more traditional investments/trading.
- Mengkudulangsat 5y agoI'm dealing with an American law firm at the moment (Baker McKenzie) that just categorically refuse to deposit BTC into my personal hardware wallet. They require I provide an address tied an account within their "reputable" list of exchanges which ironically includes Binance. Unless we fight back, the crypto space will quickly devolve into a worse version of banking.
- joejerryronnie 5y agoWait, the law firm has agreed to give you/pay you in BTC, but they won’t deposit it into a hardware wallet address you provide them? Why do they even care?
- lnanek2 5y agoThey likely don't implement any BTC support themselves, just have some other company do it that only supports exchanges?
- lupire 5y agoI'm guessing the law firm is facilitating a transfer, like someone trying to buy a house with crypto, or distribute an inheritance.
- Mengkudulangsat 5y agoYup. As for why they would care, something to do with the recent FATF travel rule I suppose.
- erdo 5y agoThat's probably related to the risk of accidentally facilitating money laundering? The exchanges are all forced to implement various "know your customer" processes
- Mengkudulangsat 5y agoFWIW, I don't mind the KYC concern. I even provided my identification documents to facilitate the process. It's the we-only-do-business-with-exchanges angle that irks me.
- codeisawesome 5y agoWhat is a competent and trustworthy guide for choosing a cold wallet strategy? There are many products on the market and none seem trustworthy. Is a raspberry pi kept offline with an external storage drive a good strategy? When the pi needs kernel patches etc, I’d unplug the drive in this scenario?
- AgentME 5y agoA dedicated hardware wallet like Trezor or Ledger is likely a much better setup than a homebrew setup on a general purpose computer.
- codeisawesome 5y agoWhat if those brands are compromised or back-doored by internal or external actors? Just look at the Western Digital fiasco recently. Do these wallets call home at all? Also: aren’t backups easier to make on a normal SSD? (PS: these are my personal genuine concerns and I’m at least somewhat willing to have my mind changed: not trolling or being argumentative for entertainment)
- AgentME 5y agoTrezor is open source, and neither of them connects to the internet directly. They only connect to open source programs on your own computer, so the ways they talk to the outside world are known.
- codeisawesome 5y agoThanks, I’ll look more deeply into this.