5 ms·
If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air
by DSingularity 4y ago
If this is true there really is such low hope for cryptocurrency. If you can’t store your keys in a service like LP hardened via physical 2FAA. What’s left? Air gapped setups?
- deleted 4y ago[deleted]
- luisschwab 4y agoSelf-custody of keys. What's the point of trustless money if you trust someone with it?
- armada651 4y agoThere's a step in between LP and an air-gapped setup, it's called "not uploading your keys to the internet".
- TedDoesntTalk 4y agoPrint out the seed phrase
- Sakos 4y agoI handwrite them, stuff them in with a bunch of other handwritten notes and make it a bit less obvious that the words belong together as a phrase.
- dan-robertson 4y agoI think lastpass is reputed to be bad compared to competitors like 1password. If you can’t secure your bike with a flimsy Kevlar belt, what’s left? A team of two armed guards?
- loopdoend 4y agoWhy would you store your private key on a cloud storage service? This is what hard wallets are for.
- nequo 4y agoPasswordless might be the way to go. We (as a society) have been trying to do 2FA now wherever we can. 2FA can involve an authenticator app but it is easier with a physical key. That physical key by itself can obsolete the password for many uses. The more numerous the places where we can abandon passwords, the fewer the secrets that we need to keep.
- kube-system 4y agoThis is the answer. The only advantage of passwords is that they’re cheap and universally compatible. PKI based solutions are more secure and more convenient. They cost a few dollars and there are too many standard, though. Ultimately, I expect the biggest barrier to be mental. People have had mantra about passwords banged into their heads for decades that they have become synonymous with a secure system and people are suspicious when their device just lets them in with little to no friction.
- LelouBil 4y agoI don't know why, but I'm still a bit afraid of using security key everywhere. I have an irrational fear of losing/breaking my security key. Even though I know my phone is fine and always with me (as a comparison). I just set up a whole backup solution for my many self hosted applications, all encrypted with the keys safely in my password manager. Even uploaded to S3, because I figured if I'm paying for it, I could ID-and-support ticket my way to my data even if I lost my AWS credentials. I don't know how to integrate a security key into this scheme. What to do if it actually gets lost ? Will I have to use emergency codes for all the accounts ? Can I make a backup of it somewhere ? Would that defeat the purpose ? I'll buy one someday, when I'll have all this figured out.
- nequo 4y agoI think that worry makes sense. It is a good idea to keep a backup. For example, you could get two YubiKeys, use one as your primary, and put the other in a safe place as your backup. It is a little bit of a hassle. But changing 200 passwords because LastPass was breached is also a hassle.
- 4y ago
- X6S1x6Okd1st 4y agoThis seems like an aside, but I'd love to see smart contract wallets with velocity send limits, or time locked whitelists as well as social recovery
- bigiain 4y agoHere we see the crypto world continuing their speed run of reinventing the banking system, and discovering daily atm withdrawal limits.
- paulpauper 4y agoDo encryption on offline computer with trusted open source encryption solutions. Why do you think bitcoin experts have always said to do everything offline?