8 ms·
> the "lose your key, lose your wallet" thing is fundamentally incompatible with real users. You're allowed to store your key at the bank if this is an issue f
by soerxpso 2y ago
> the "lose your key, lose your wallet" thing is fundamentally incompatible with real users.
You're allowed to store your key at the bank if this is an issue for you. It's less secure than memorizing it, but obviously equally as secure as your bank account is.
- throwaway290 2y agoIt is not equally secure, if bank loses you money you have recourse, if bank loses your key (a fire, a flood) it's gone.
- perceptronas 2y agoYou can store it in two or N places. Or bank can do this for you.
- throwaway290 2y agoMore places is more opportunities for the baddies to get it.
- kriops 2y agoShamir it.
- sulandor 2y agoplease wrap the whole thing as a trustworthy product
- cooljoseph 2y agoI don't understand why this was downvoted. In case it's not clear: (S)he's saying to split the key into multiple shares that can be used to reconstruct the key if you have a large enough quorum. Then store each share in a different place. As long as you don't lose too many of the shares, you'll be fine. And one baddie is NOT enough to get the key.
- throwaway290 2y agoEither shuffling those keys stored in N different deposit boxes is overly complicated for a normal person, or it is not overly complicated for a moderately dedicated baddie either
- Djdjur7373bb 2y agoUnless the "baddie" in this case is the government, why would it be easy for anyone to obtain access to multiple secrets stored in multiple boxes/banks? Multisig is a pretty common setup for crypto and there is software that makes it easier.
- throwaway290 2y agoCan you show how it can be easy to use in normal life for a regular person and at the same time really difficult for the attacker?:)
- notfed 2y ago"Mom, I already told you: you have to generate a key pair, split the private key into three parts using Shamir' secret sharing algorithm, then give each part to three banks. Whenever you want to use it, you have to go collect it from each of those banks---but DON'T write it down anywhere---and perform your transaction" And to think the conversation started with an observation that people can't even remember one password.
- rkagerer 2y agoI agree, there's miles of runway remaining for improving the UX. I actually think it'd be neat if a crypto had this (and a few other things) as a baked-in feature. i.e. In order to create a wallet in the first place, you need to identify e.g. 5 trusted friends who'll serve as recovery partners. Maybe it's initially tied to the same invite mechanic used to join the ecosystem. Could be done in a privacy-preserving (and to some degree anonymity-preserving) fashion. The right UI could make this even simpler than recovering a Gmail account. Everyone would just have it set up, and these conversations about losing your keys would be a relic of the past.
- tomhallett 2y ago"soerxpso" said "store your key at the bank", but you are saying "two or N places". So it sounds like 1 bank is less secure for your key then 1 bank is for your money, because you need two or more banks for your key, while 1 bank for your money is sufficient. Correct?
- afastow 2y agoI stay away from everything crypto but I don't see the difference. In both cases if they didn't make it right you'd go to the courts and make your case that they are at fault and owe you compensation.
- kgwgk 2y agoIn the first case, bank deposits are insured. In the second case, safe deposit boxes are not insured.
- afastow 2y agoThey're just different things. The FDIC insurance is for if the bank itself goes insolvent and they literally don't have enough money to cover their depositors' balances anymore. There's no reason a safe deposit box would be affected.
- throwaway290 2y agoA fire, a flood, a robbery...
- bburnett44 2y agoIs a bank deposit box not insured against those things? I've never really thought about it but always assumed they would be
- dagw 2y agoProbably varies from bank to bank, but in my experience you have to specifically buy separate insurance if you want the content of your deposit box insured. The big problem from the bank's point of view is that, unlike your bank account, the bank doesn't know what you have in the box and thus has no idea what to insure it for and no way to verify any claim.
- 2y ago
- generic92034 2y agoI might be mistaken, but are not several "traditional" banks offering crypto wallets for customers? Is there a realistic chance this kind of bank is going to steal their customers' crypto and going (at least, next to criminal investigations) bankrupt over it?
- Djdjur7373bb 2y agoSure, they could. Would that be any different from how a bank could steal funds from a traditional deposit account? By making a bank the custodian of your crypto wallet, you're placing your trust in them and should have similar legal recourse you would have had with a fiat deposit.
- generic92034 2y agoI am not sure if you are objecting. Definitely you need to trust your bank if you are going store your crypto with them. I just do not see any large traditional bank stealing their customers' crypto and hoping to get away with it. As far as I know all the cases of stolen crypto have been newly founded companies with their only business being your crypto. That is quite unlike the other kind of bank.
- Vegenoid 2y agoAre you referring to a physical lockbox? Because if so, that is certainly not as secure as your bank account, because criminals could not drain your bank account by breaking into a bank, nor could your account’s funds be lost if the physical location were destroyed by a flood or other disaster. Even if you are referring to digital storage managed by the bank, presumably competently enough to avoid data loss, if that data is exfiltrated your wallet will be drained. It would be very difficult for a hacker to irreversibly drain your bank account (given the type and terms of the account, but will apply to most savings accounts), due to the protection and delay systems in place meant to catch fraudulent or unauthorized activity. Note that this definition of “unauthorized” actually means “not authorized by the human being who owns this account”, instead of the crypto definition of “not authorized by someone who knows the correct secret”.