5 ms·
If you hold a large amount of bitcoin your threat model should be way above the average person. It sounds like his infrastructure was specifically targeted. It
by jtchang 4y ago
If you hold a large amount of bitcoin your threat model should be way above the average person. It sounds like his infrastructure was specifically targeted. It can be very difficult to protect against targeted attacks from adversaries.
- Alex3917 4y ago> It can be very difficult to protect against targeted attacks from adversaries. Not really. The device used to sign transactions should never be connected to the Internet.
- tsimionescu 4y agoIf the level is millions of dollars, that device could be physically stolen, or some aspect of the cryptography/auth scheme could be attacked through a 0-day. Of course, it's also possible he just wanted something closer to the convenience of a bank account/credit card instead of a pile of cash and failed in the opsec.
- lampshades 4y agoThat’s why you don’t store millions of dollars in your physical location. You break up the seed and disperse it among several bank lock boxes. (See https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing) https://en.m.wikipedia.org/wiki/Shamir's_Secret_Sharing). Keep a small amount in a hot wallet for convenience and a larger amount (but not too large) in a cold wallet accessed via hardware. But the bulk shouldn’t be accessible without breaking into at least two lock vaults.
- tsimionescu 4y agoWhy just two lock vaults and not some army bunkers, together with the nuclear codes preferably? At some point this level of care becomes more than absurd.
- lampshades 4y ago> makes up hypothetical situations > attacks his own hypothetical situations
- m-richthoven 4y ago[flagged]
- tsimionescu 4y agoNo, I was attacking your idea that it's somehow common sense that the best way of storing BTC is by working with multiple banks (!!!) to store various key fragments, by showing a more extreme version. Of course, if someone did follow your example, and then the government compelled the banks to hand over access to the physical tokens, other people similar to you would come out and say "not your keys, not your bitcoin", or insist on even more byzantine forms of secret protection. Not to mention, with your proposed scheme, actually using your BTC becomes significantly slower than any international bank transfer.
- lrvick 4y agoWhat do you think banks do? When you store a -lot- of value like a pile of gold bars, you are going to need more than a foam and aluminum hotel safe.
- tsimionescu 4y agoFor me as a consumer, storing money in a bank is far simpler and more convenient and more likely to not get me burned than it is to store various hardware tokens with various banks (having to physically retrieve them when I actually want a purchase). So, if the only way to secure BTC is to this cold wallet dance, then it's clear BTC is not a usable store of value compared to USD.
- lrvick 4y agoThe only way to secure a -lot- of BTC. Or you can pay a custodian to do it for you. You have the same options as cash. Most people do not store millions in cash or gold at home.
- thinkmassive 4y agoShamirs still requires having the (single) private key present for signing. Multisig is far superior for Bitcoin security. The keys can remain geographically separate at all times. Each signing operation requires only the partially signed transaction (PSBT) and the other public keys.
- lrvick 4y agoNon-issue if you only use the key once, then do a new split each time. Plenty of tooling exists to make this easily in reach with a simple shell script.
- thinkmassive 4y agoWhy would you use Shamirs when the Bitcoin protocol has a superior mechanism built in? SSS is a good solution for other key material, and for storing a paper key to be used for recovery purposes, but it's completely inferior to multisig for normal management of a shared and/or large Bitcoin wallet.
- lrvick 4y agoWell, bitcoin is not the only type of secret one needs to protect. GPG keys, other cryptoassets, password manager master encryption keys, etc etc. I like to have one solution that can work for my entire cryptographic life.
- unusualmonkey 4y agoI just love the idea of going around creating accounts at multiple different banks for storing of parts of the key. Then, when you're finally ready to access you funds, creating appointments at all those different banks, driving to them all, and then finding out enough of the keys are completely missing that you now cannot access any of your funds: https://www.nytimes.com/2019/07/19/business/safe-deposit-box-theft.html https://www.nytimes.com/2019/07/19/business/safe-deposit-box... Or... you know... you could just store your funds in one or more bank accounts.
- walnutclosefarm 4y agoA great success for the idea that your BTC is a store of value not dependent on traditional financial infrastructure - now it takes the a whole morning and cooperation of 3 banks for you to get at your money.
- krisoft 4y agoNot really? “Targeted attack” can mean many things. If you have control over wast sums of hard to trace treasure a determined attacker might just kidnap you and/or your loved ones, and win your cooperation using threats of violence. Your suggested safety precaution is a sensible start, but far from enough if you have a lot of bitcoin.
- deleted 4y ago[deleted]
- green-eclipse 4y agoIncredibly difficult to defend against nation state attackers and such. North Korea is very persistent in crypto hacks, for example: https://www.npr.org/2022/12/22/1144996480/crypto-hacking-north-korea-billion https://www.npr.org/2022/12/22/1144996480/crypto-hacking-nor...
- paulpauper 4y agoif something is cryptographically secure, it should not matter how big the threat actor is
- blibble 4y agoany goon-for-hire can break into your house and hit you until you tell him how to get the bitcoins out https://imgs.xkcd.com/comics/security.png https://imgs.xkcd.com/comics/security.png
- lrvick 4y agoIt is actually really simple, albeit tedious, to defend your bitcoin against remote state actors. Do keygen and signing with reproducibly built binaries on a reproducibly built minimal OS and never connect it to the internet.