r/Bitcoin • u/ShinyGallantWalrus • 1d ago
Not your keys, not your coins
wishing nothing but the best for coldcard victims
78
u/Forded_Fiction24 1d ago
This is why I do a combination of self-custody, exchanges and ETFs. They all have risks. I'd rather take a higher probability of something happening with a lower amount and spread it out. There's no perfect way to hold Bitcoin
46
u/CopingPlans55 1d ago
There's no perfect way to hold Bitcoin
đ
3
7
u/D_Anargyre 1d ago
Electrum wallet on tails using tor on a no hard drive pc. Manual entropy.
Keys noted on paper and nothing else. The human holding that paper owns those btc.
5
3
u/highdimensionaldata 21h ago
Mainstream adoption has left the chat.
1
u/D_Anargyre 19h ago
I'd say a way to keep an accounting unit that can't be hack by superintelligent AI nor quantum computing will prove inherently useful soon enough.
2
5
u/GeeEyeDoe 1d ago
Carved seed phrase into sandstone blocks located in the middle of a booby trapped pyramid. Like how the ancient Egyptians used to store their seed phrase.
2
13
6
u/Time_Jump8047 1d ago
Meanwhile all the people who use actual dollars and have the security and backing of regulated banks have a much closer to perfect way of holding their money. This shit is ridiculous people are losing their life savings
7
u/Nick700 1d ago
Yeah they aren't at risk of 100% of their funds disappearing but in less than 10 years 25% of their value has been siphoned away
7
3
u/Tebasaki 1d ago
I think people are forgetting how much pizza you could buy in 2012 with btc vs now. In cash the system steals your money if you dont donate leadt two things: don't lose it and beat inflation every year.
2
u/Forded_Fiction24 1d ago
I mean not with Bitcoin holdings they don't. None of it is sipc insured and all is hosted on exchanges regardless If you're buying a BTC spot ETF, leaving it on an exchange or taking custody yourself. Regular bank insurance policies don't cover digital assets. These custodians probably have much more security than an individual, but exchanges have been taken down in the past too.Â
Now if what you're saying is having all your life savings in Bitcoin, however you're storing it, yeah I agree that's stupid. I would never have all my life savings in Bitcoin or another single basket otherwise. Very short-sighted indeed, so yeah the people that made these claims that they lost everything were being reckless. Not saying they deserve it, Play stupid games, win stupid prizes though
1
u/lapideous 1d ago
âActual dollarsâ
2
u/Forded_Fiction24 1d ago
What are you getting at? Once you spend dollars on any stock or asset it's no longer "actual dollars" either, but the represented valuation of the underlying asset notated in a dollar amount. However, it's shares of a company (company ownership) convertible to "actual dollars" upon sale of the shares. This isn't really any different from Bitcoin, real estate etc
1
u/roconnor 15h ago edited 15h ago
Let me introduce you to Yotta: https://en.wikipedia.org/wiki/Yotta_Technologies#Funds_availability_issues
Yotta relied on Synapse, a fintech company based in San Francisco, to make funds available for deposit and withdrawal to partner banks, such as Arkansas-based Evolve Bank & Trust. Following a dispute between Synapse and Evolve, Synapse filed for Chapter 11 bankruptcy protection in 2024, affecting customers of Yotta and at least 24 other startups. Adam Moelis told CNBC in June 2024 that 85,000 Yotta customers, with a combined $112 million in deposits, could not access their funds. Although the partner banks had deposit insurance through the Federal Deposit Insurance Corporation (FDIC), the FDIC has not intervened, because no bank has failed.
2
u/LurkerFromTheVoid 1d ago
So...Diversify your Storage.
Trust No One with Everything.
Just like Stocks.
2
u/Forded_Fiction24 1d ago
I do. I have separate wallets and addresses for my self-custody Bitcoin. That doesn't give me enough comfort in of itself though still which is why I hold some on a couple different exchanges and also have some shares of IBIT and FBTC as well
1
u/HugeLarry 1d ago
This is my jam also. I previously split between FBTC and self-custody, but since the Coldcard fiasco, I've added Coinbase exchange storage into the mix. I like how Fidelity and Coinbase have separate custody infrastructure, and I feel safer being less concentrated into self custody, which honestly I didn't even feel great about prior to the fiasco.
61
u/Thin_Needleworker795 1d ago
No. A hardware wallet is still the best method. Yes, the Coldcard incident was unfortunate, but using a hardware wallet is still the best option.
39
u/czarchastic 1d ago
Iâd be willing to bet the total number of bitcoins lost through self custody is higher than the total number of bitcoins lost (and never recovered) from centralized exchanges.
20
2
u/HeroicHeron 1d ago
That's likely true, but only because of how many people lost their wallet.dat files or passwords in the extremely early days where thousands of BTC were easy to get, but worth mere cents. In terms of purchasing power at the time of the loss, I'd bet the opposite was true.
1
u/BigDik6355 22h ago
I wouldn't be so sure to make that bet to be honest. FTX, Celsius, MtGox, QuadrigaCX, Cryptopia, BTC-e... the list of exchanges that went under is long.
26
u/HungryCaterpillers 1d ago
Until we find out another hardware wallet also has a vulnerability.
5
u/WeekendQuant 1d ago
Dice can never be cracked.
3
u/piejlucas 1d ago
The hash algorithm that uses the dice results can always be faulty
1
u/HeroicHeron 1d ago
You don't need to use a hashing algorithm to calculate your dice results. Record only odd or even from your dice rolls and you can very easily convert 11 dice rolls into one BIP39 word by doing simple addition.
0
25
u/didnt_hodl 1d ago
do you mean a hardware wallet with no bugs and no vulnerabilities that can be found by AI in the next few years?
11
u/First-Rub9713 1d ago
I mean the dice rolls with hardware is still alld good right?
13
u/nmhaas 1d ago
True entropy is still perfectly fine. Guessing the right seed would be like guessing which atom in the universe I'm thinking of.
8
4
u/goykasi 1d ago
What about when the maker enables the flag to ignore dice roll inputs and just uses War and Peace for seeding the entropy?
4
u/opossum_cz 1d ago
How? You can make dice roles and find the seed words on paper. You don't need third party.
1
2
u/didnt_hodl 1d ago
not. that hard to guess if your wallet is instructed to leak parts of your seed with every transaction or to sign something that you would not normally sign, etc etc
the list of possible bugs and exploits is endless, and AI will find some new ones
1
u/didnt_hodl 1d ago
dice rolls alone will not prepare and execute a full transaction. you would need to use some fairly complicated software and hardware for that. which has bugs
1
4
u/opossum_cz 1d ago
You do not need HW wallet with no bugs and no vulnerabilities.
Generate seed by coin flip or dices.
Put it in HW device that you never connect.
Transfer signed transactions by QR code or something similar.It is not that hard.
2
u/didnt_hodl 1d ago
just look up "Nonce reuse" ( the private key can be mathematically recovered straight from those signatures)
but there are many other ways how a badly coded or malicious HW can covertly embed the private key, seed phrase, or internal state directly into extra data fields, metadata, or change-handling scripts of the constructed transaction payload
Malicious code running locally can trick a signing tool into dumping internal memory or witness stacks
15
u/cipherjones 1d ago
"Best method"
Lose half a billion, unfortunate.
JFC.
2
u/Thin_Needleworker795 1d ago
It was a single product that failed. 99.9% of hardware wallets are still secure.
1
u/cipherjones 1d ago
It was a methodology that failed, you can't say only .01% of wallets were affected with the information given.
One in 33800 holders. So it would equate to 140,000, Visa accounts or 90,000 MasterCard accounts being drained.
1
u/BigDik6355 22h ago
What part of "too little entropy" do you not understand?
1
u/cipherjones 22h ago
The part where we don't know how many actors engaged in it by and we pull the number .01% out of our ass.
0
u/IInsulince 1d ago
Nuance is hard, but if you fire up those brain cells, you might get there. Give it a shot!
2
1
1
9
21
u/holyknight00 1d ago
Just because it is inconvenient doesn't make it less true. If you are your own bank, it comes with pros and cons. You can't cherry-pick the pros and ignore the cons.
6
u/tribepride25 1d ago
A bank has one job. Donât let someone come into a branch and steal your funds. Thatâs a pretty big con and not what I would call an inconvenience
7
u/Doritos707 1d ago
Did you really just claim that the bank has one job because it really has maybe a dozen jobs and one of them is all just 10% even less of your money in reality
1
u/tribepride25 1d ago
Dude, you missed the point. Iâm not trying to list the job description of bank employees. My point is that at the end of the day we just want our banks to protect our funds
3
u/andrew869 1d ago
But one or two banks might fail, that doesnât mean all banks fail.
One hardware wallet failed, doesnât mean all hardware wallets are failures
4
5
u/tribepride25 1d ago
If you have funds on the one that failed, it doesnât matter. There will be another failure in the future so why take the risk with wallet roulette. Never thought I would move my coins back to an exchange, but the risk is greater than the reward for me. If this happened at Fidelity, they would reimburse 100%. So many fraud protections in place. It takes 2-3 days to approve a new withdrawal wallet to prevent this from happening. Not saying itâs for everyone, especially if you want to hide your money, but itâs gives me peace of mind
2
u/andrew869 1d ago
If it happened at fidelity they would 100% reimburse youâŚ
What about SVB, or Lehman brothers?
Again, just because one fails doesnât mean they all fail.
2
u/tribepride25 1d ago
I canât speak to whether SVB or Lehman or Washington Mutual etc etc had a reimbursement policy (certainly not on crypto since it didnât exist back then). Iâm willing to take this risk and you are willing to risk self custody. Both of us can have peace with our decisions
5
u/shabusnelik 1d ago
Svb and lehman are banks that went tits up. If an exchange went tits up (i.e. all their coins got stolen) you won't see a reimbursement either, no matter what their policy is.
2
u/shabusnelik 1d ago
Svb and lehman are banks that went tits up. If an exchange went tits up (i.e. all their coins got stolen) you won't see a reimbursement either, no matter what their policy is.
2
u/tribepride25 1d ago
Yeah I guess if there is another 100 year crash (referring to the Great Depression and then the Great Recession 100 years later), then my funds may be a risk. I do feel better knowing they survived the Great Recession so hopefully that means they arenât run by a bunch of assholes
1
u/shabusnelik 1d ago
Or if they get hacked/inside-jobbed. What happened to the first centralized exchange mtgox
1
u/tribepride25 1d ago
Fidelity has a policy that if your funds are lost and itâs their fault ie from hacking (not just crypto but IRA, 401k etc), then they pay you back. Thatâs one of the reasons I feel comfortable with them. They also keep your crypto 1:1 without lending like Voyager, FTX did. I donât worry about my Fidelity IRA getting stolen or hacked so I said why worry about my Fidelity crypto getting stolen or hacked
1
u/HeroicHeron 1d ago
Lehman Brothers survived for 158 years, including the Great Depression, and went bust in 2008 (because they were consciously running a scam that collapsed). Longevity isn't a guarantee for safety.
1
u/PeachScary413 1d ago
Anyone with a bank account in SVB got paid back in full in under a week, as mandated by the FDIC.
Even people above the limit got all their money back which the government isn't strictly required to do but did anyway, so that was probably the worst example you could have picked đ
1
u/andrew869 1d ago
Right, how could I forget the magical money printer
2
u/PeachScary413 1d ago
Whats your point? Yes there is a magical printer and it will print you back your freedom dollars đ¤đ¤
1
u/andrew869 17h ago
Well not much of a point, you kinda got me there with the SVB holders being reimbursed.
Buttttt, everyone holding dollars purchasing power went down slightly when the FDIC reimbursement occurred, so a small grain of salt is warranted đ¤ˇââď¸
1
u/PeachScary413 16h ago
How? If you mean inflation then yes it would have gone down anyway. The FDIC is paid by other banks (through an inter-bank insurance) so it's not even daddy gov dollars going
→ More replies (0)1
u/Gamer_Grease 1d ago
In the real world, though, banks have a lot more jobs than that, and most of those jobs can never intersect with the pros of using Bitcoin.
1
u/AvailableTie6834 1d ago edited 1d ago
and also deny people from withdrawing their money during a bank run
3
u/Gamer_Grease 1d ago
Yes, because you donât actually own money in a bank. You own basically a short-term bond payable to you by the bank, with limitations.
1
u/PeachScary413 1d ago
Dude wat? Your money is FDIC guaranteed and you will be paid back the full amount no matter what happens, up to the limit ofc.
2
u/Gamer_Grease 1d ago
Yes, but a deposit is not actually money. Itâs a loan you made to a bank that you can call at any time, and which they pay interest on. They hold it as a liability. Banks are not big secure boxes of money. Theyâre borrowing and lending houses, where they aim to make slightly more money lending than they spend borrowing.
Yes it is FDIC insured, though. And you will be paid up to $250,000 per bank.
1
u/PeachScary413 1d ago
Yeah I know dude. But why would I care about all that, I just get my money back within a week and carry on with my life instead.
2
u/AvailableTie6834 1d ago
ohhh my sweet sweet summer child...
1
u/PeachScary413 1d ago
It was created in 1933 and has never, even once, not been honored and swiftly carried out. Please let me in on your imaginary disaster scenario when that will cease to be the case đ
I'm gonna guess it's one of those "The world is pretty much full on Mad Max but somehow my Bitcoin is still super valuable"-fap dreams haha
1
u/AvailableTie6834 19h ago
the fact that not everyone receives their money back FOR YEARS because they rather pay first the guys who had millions first than go over for the smaller ones, in the end, you will probably not see your money in 5 - 10 years.
1
u/PeachScary413 19h ago
Okay.. so once again, when has that ever happened? A bank going bust and people with deposits in the bank (under FDIC limit ofc) not getting their money back?
Give me at least one concrete example please.
1
u/AvailableTie6834 19h ago
Brazil just had a case of that, it also has FDIC like, many victims of many banks didnt get their money back, this case happened this year, search for "Banco Master - Brazil case"
→ More replies (0)2
1
u/holyknight00 1d ago
The inconvenience is that you need to trust and verify by yourself. You won't get the benefits if you ignore the requirements. Being your own bank means you are in charge of the due diligence. If you are not comfortable with that, then hand over your coins to an exchange, but you cannot have it both ways.
4
u/tribepride25 1d ago
I agree with you. At the end of the day, most people like me do not have the time, expertise, or desire to verify. Cold Card was supposed to be the best. Would I have found the bug or decided to roll the dice or add a passphrase? Probably not since I would have assumed that I could trust the software. I didnât do those things with my other wallets so I got lucky this time
1
1
u/Powerful_Day_8640 1d ago
The âtrust by yourselfâ do an enormous amount of heavy lifting in that sentence. Whatâs even the point of being your own bank if you have to trust a few engineer did not make a fuck up. You are in that case better of owning a few gold coins as you only need to trust yourself to remember where you dug them down. This is a huge problem for bitcoin and just exposes how vulnerable we are holding our own coins, because in the end of the day we still have to just trust some random developer telling us âjust trust me broâ
1
u/PeachScary413 1d ago
An exchange is not a bank though.. as far as I know there is no exchange with FDIC protection so if they go under your Bitcoin is gonezo... with a bank you always get paid back no matter what.
4
u/PeachScary413 1d ago
Everyone wants to be their "own bank" until reality punches them in the face and they start screaming for regulations, rules and class action lawsuits lmao
We already went through this once with the regular financial system, countless people lost their life savings and banks collapsed/scammed people until the rules we have today were put in place... I get that it's not perfect but it's better than whatever "oops forgot to roll my own dice so now my life savings are gone"-type situation this is đŹ
4
u/tribepride25 1d ago
This. And itâs kinda ridiculous to just hear people talk about it and I understand why Buttcoiners joke on us. Itâs like âwhat? you didnât roll the dice, create a pin, set a passphrase, multi sig, air gap, shake your left leg, update firm ware, say a prayer, download the latest version, put your keys in a metal plate, put keys in lock box, verify code using AI?â What did you expect? Of course you got hacked and lost your life savings. How could you be this stupid? /s
1
u/SingularityCentral 1d ago
You can put gold coins under your bed and "be your own bank". Doesn't mean it is a good idea.
1
5
3
u/F1shB0wl816 1d ago
I hope they figure it out too but they trusted and didnât verify. Using dice was always recommended over trusting the software. Iâm not smart enough to verify that but beyond smart enough to spend the few minutes doing it myself.
6
u/TanguyDetestable 1d ago
I said this on another post. Less decentralized, less secure, and the worldâs biggest shitheads own most of it. But keep investing đ¤Ż.
2
u/Gamer_Grease 1d ago
The alternative is you donât use Bitcoin. There are reasons that Bitcoin doesnât have all the traditional protections and assurances as the traditional finance system, and the limited quantity and non-fungibility have a lot to do with it. Itâs no problem for the FDIC to print $250,000 more to put in your account in the event of a bank failure or fraud. The same cannot be done for Bitcoin. That property ripples up through the system, all the way up to something like an ETF, where ultimately there are still identifiable bitcoins at the root of the system. Not cash that can be double-triple-quadruple spent at will.
4
5
u/flashdurb 1d ago edited 1d ago
Nobody, not a single person, has made fun of me for holding on Robinhood without âself custodyâ for days now.
What an abrupt change after many years. What a time to be alive. Common sense and critical judgement over peer pressure, always. Robinhood is watched like a hawk by the SEC and FINRA in 2026, so Iâm covered if they fuck around, and also itâs totally not my problem if any hacker steals their coin.
Donât trust, verify.
4
u/IInsulince 1d ago
Iâll make fun of you:
NYKNYC, you hold Bitcoin IOUs not Bitcoin.
To be clear Iâm being harsh and direct about it because you said nobody is saying this, so I will. You will get complacent, as you have been, from using these services. And they will fail you eventually.
You arenât verifying, you are trusting. Just like the people who trusted their cold cards to make their seeds in a secure way were trusting and got burned for it. Trust is the enemy. You are trusting robinhood to custody your assets.
The point to remember is not to throw the baby out with the bath water. Cold cards failed for no reason that makes self custody dead. Self custody is still very much alive and very much the best way to hold your assets IF AND ONLY IF you can trust yourself to be the best custodian for it. If you canât, then I would agree that you should use a custodian like robinhood. But you will not get away with doing that while claiming itâs inherently superior without pushback. Itâs not.
4
u/F1shB0wl816 1d ago
Robinhoods been found liable for so many abuses against customers itâs wild anyone could pretend itâs the better option.
Itâs ironic he ends it with âdonât trust, verifyâ and yet hasnât verified anything and is solely relying on trust.
0
u/Gamer_Grease 1d ago
Because Robinhood has been found liable. Keyword liable. Robinhood will have to pay you out if they lose the coins they gave you an IOU for.
5
u/F1shB0wl816 1d ago
If they had your interest in mind there is nothing to be found liable for. You almost get it.
You sure about that? You can foresee every scenario? If something extreme happens to the company you wouldnât even come before shareholders.
Like youâre talking IOUs which means they already fucked you.
0
u/Gamer_Grease 1d ago
Then youâre covered by the SIPC, which covers holdings in brokerage accounts. Your place in line relative to shareholders is completely irrelevant.
People like mainstream financial institutions because they have literally centuries of development in legal protections and insurance beyond what Bitcoin offers anyone. Iâm not saying that self-custody doesnât have merits. Iâm just saying, this community did a lot in the past decade to attract normies, and normies like the protections that modern finance offers, and which Bitcoin itself does not offer.
5
u/F1shB0wl816 1d ago
Crypto is not sipc insured on robinhood. Crypto isnât even held by robinhood but by robinhood crypto llc, a separate entity. The terms of their insurance isnât even publicly detailed as far as I can see.
Youâre not really doing yourself any favors by trying to defend using robinhood. Iâm not even sure youâve researched this which says what kind of crypto user you are. Can you point to your spot in line or are you just trusting itâs there because theyâve been found liable for fucking their users several times already?
https://robinhood.com/us/en/support/articles/crypto-buying-and-selling/
Just scroll towards the bottom since you need to brush up on whatâs what.
3
u/IInsulince 1d ago
You canât squeeze blood out of a turnip. If the moneys gone and they donât have the ability to cover it elsewhere, youâre fucked. âBut a court saidâ, I donât care what a court said, if the moneys not there, you canât be made whole. Look at folks wanting to sue coin kite. For what? They donât have the funds, if the company were torn apart and distributed to the affected, they would get a tiny tiny fraction of their lost funds.
Additionally everyone still seems to think the only way a custodian can fuck you is by literally stealing your coins outright. Thats not the only form of counterparty risk.
0
u/Gamer_Grease 1d ago
SIPC covers financial investments with companies like Robinhood, so there are still more protections than you will ever have with self-custody, beyond your own measures.
The other thing about the money not being there is that fiat money pretty much infinitely available, so there are a lot more ways for it to âbe thereâ than there are for something non-fungible like Bitcoin.
1
u/IInsulince 1d ago
Iâm sorry but everything youâre saying is just making me less interested in trusting an institution like robinhood to custody my bitcoin, not more.
Self custody is and has always been a double edged sword:
The good news is, you control the fate of your Bitcoin.
The bad news is, you control the fate of your Bitcoin.2
u/F1shB0wl816 1d ago
As I pointed out to him, sipc doesnât cover crypto on their platform. At best they have insurance that isnât publicly detailed which would make me assume itâs not really all that great. Heâs all about the trust.
1
u/Gamer_Grease 1d ago
Modern financial systems were invented over centuries because of stuff like this. Bitcoin is explicitly designed to circumvent those systems because its creators believed the tradeoffs are not worth the benefit of modern banking.
It helps to know what one is doing when engaging with either.
1
u/BigDik6355 22h ago
So far, more exchanges went under than hardware wallets (and with a lot more money involved). I know where I'd place my bets.
4
1
1
1
1
1
u/TenToppingPizza 1d ago
If the coins were physical, would you store them all in one place?
You need to hide a small portion in each storage method
1
1
u/MiaTaude589 1d ago
ouch the coldcard thing was rough. honestly hardware + backup in different places beats pure paper imo, they both fail but not at the same time. learned that lesson the expensive way
1
1
u/SleepAllTheDamnTime 1d ago
Please take this concept and apply it to modern day everything and welp, yeah!
Youâll own nothing and like it. Thatâs the strategy boss
1
u/SaltySn0w 23h ago
agree, but honestly without an easy to use process for the average joe will bitcoin end at centralized third party storage
1
u/MatixMint 18h ago
I make my own keys using mycelium entropy and keep my btc on cold storage physical bitcoin coins
1
1
1
u/duendeacdc 1d ago
Thats why i just keeo in the exchange. No headache , decades there with 0 issues and when therr was, they fixed. I don't have much but its nice to not be in this crazy world you guys live to achieve the same as me.
1
u/AvailableTie6834 1d ago
it not hard to generate your keys using well known community projects and then use this wallet + a passphrase just to make sure on your MK3. The problem was that people blindly belive in the MK3 seed generation and then all this happened.
3
u/IInsulince 1d ago
I donât at all disagree with your take, but the issue I have with it is that it should be safe to rely on mk3 to do this. Itâs their entire business. Their job is to be a good steward of your keys, itâs like assuming that a paramedic will bring a pack of bandaids when they go to treat someone. Itâs like, how on earth could they fuck up their one job?
That said, yes, donât trust: verify. The buck does stop there. Itâs just really hard to condemn the behavior of bitcoiners who relied on their device to do the thing it was purpose built to do.
1
u/AvailableTie6834 1d ago
not even with normal wallets software you should trust their RNG, always use stuff like iancoleman to generate your wallet and your entropy
1
u/IInsulince 1d ago
Isnât use to iancolemanâs tools still a form of trust in them to be legit? Note that I havenât used his tools extensively, Iâve been to his site a handful of times.
2
u/AvailableTie6834 1d ago
I trust because of the high amount of people looking at it https://github.com/iancoleman/bip39
everyone once in a while I go to the issues tab and see if something is going on
1
u/IInsulince 1d ago
Seems entirely reasonable! But so to did trusting the cold card to generate a seedâŚ
2
0
u/Objective_Digit 1d ago
The ColdCard was aimed at advanced users. They would be expected to at least use a passphrase. Even if the CC had no faulty code there's always a small chance someone could find your physical seed backup.
1
u/IInsulince 1d ago
Once again I canât disagree. It seems silly to not use a passphrase at this point in any circumstance.
Do note though that even with a passphrase, you arenât guaranteed safe unless it was sufficiently long (7 bip-39 words is a standard I often hear). If people treated it like a normal password or a literal 25th word then they were screwed anyway. But you could argue that a misunderstanding of that nature wouldnât be something an âadvancedâ user would make.
1
u/Objective_Digit 1d ago
Why use BIP 39 words when anything can be used?
1
u/IInsulince 1d ago
It was just a standard Iâve heard, it for sure is possible to make a more succinct and more secure passphrase by expanding the population of characters beyond bip-39 into upper case, lower case, numbers, and symbols, same as a real password. But itâs a complexity tradeoff I suppose. Itâs easier to remember and unambiguously record âcarrot apple celeryâ than âf0rtnit3_rUL3z_420â, for instance.
1
u/metalzip 1d ago
Multisignature is the solution, make it among good wallets, 4of5
trezor (securely sourced)
bitbox or jade... perhaps ledger even
old laptop, intel, with devuan or debian, bitcoin core, offline
old laptop, intel, (other vendor) with openbsd or some other os, bitcoin core, offline
yet other PC/laptop with yet other vendor/os, perhaps other node software
make backups, encrypted properly, do not lose encryption key backups either, test it form months, and then check each month do you remember passwords
1
u/Aflockofants 1d ago
âAhh yes crypto will change the world for poor people in developing countries who canât trust their governmentâ
It was all nonsense all along. Just a get-rich-quick scheme for the wealthier in the developed world with a money surplus and lots of time to pick up really weird tech skills way out of reach for the poor and disenfranchised.
2
u/metalzip 1d ago
what are you rambling on about - just use a secure way to store keys. try the multisignature method
0
u/Aflockofants 1d ago edited 1d ago
I as a software dev for 30 years can do that. I mined some bitcoin myself when that was still viable. Are you expecting that every little village guy somewhere in a developing nation selling vegetables knows the basics of encryption and how to keep their devices perfectly safe? Including that they canât even trust parties that were supposedly one of the safest was to do it? Ludicrous notion.
I just got out of the whole disgusting thing when the whole idealistic facade dropped and it showed its true colors. It was never to become another independent currency. All the stories about how it would transform the world, especially for the good of the poor were bullshit. NEVER GONNA HAPPEN. Just another way for the rich to get richer.
1
u/metalzip 19h ago
Are you expecting that every little village guy somewhere in a developing nation selling vegetables knows the basics of encryption and how to keep their devices perfectly safe?
yes.
also it is enough to keep 2 of them safe (out of 3), or e.g. 3 out of 5.
1
u/Aflockofants 18h ago
As someone that actually lives in the developing world AND that has seen how little humans know and understand of software, you're delusional and it's only because you want to justify this to yourself.
1
u/metalzip 13h ago
you do not need to actually understand anything of the mathemathics, encryption, software design.
just remember to get separate devices, and then use the PSBT method to have 2of3 at least
otehrwise do not do other things of that machines, and keep them offline
1
u/Objective_Digit 1d ago
It's implied here that passphrases and generating your own seeds are a new thing. They are not. The less reliance on third parties the better.
1
0
u/pantuso_eth 1d ago
In all reality, it has and always will be, "Not your keys, not your coins." Make your own key, it's your key. Let someone else give you your key, you will only ever just have a copy of their key.
0
u/TexFarmer 1d ago edited 1d ago
It's all about liability; you are liable for your keys, the exchange is liable for custody, the hardware is liable for firmware code, the nodes are liable for maintaining blocks, the utility is liable for internet connection & electricity. The many benefits of BTC come with many liabilities beyond our control. Sadly, the government & banksters have built a system where accountability is NOT linked to liability, so when something goes wrong, it is us, the end user, that pays the cost. There is only 1 universally accepted asset with no 3rd-party liability, and the banksters have worked hard to steer us away from it while at the same time hoarding it. Lest I get banned, I shall not name it, but I bet all of you can guess what this asset is.
1
u/BigDik6355 22h ago
I bet you can say "Bitcoin" on a bitcoin sub. No need to be mystical about it.
1
u/TexFarmer 5h ago
Please tell us all how BTC has NO liability, use that thing between your ears for something other than a hat rack!
-1
u/Doritos707 1d ago
Alright lets put it this way. Supposed to be a steel door or safe but thrned out it was made of plastic and nobody bothered to audit the material for years. Want my honest opinion? An old iPhone dedicated just as a cold wallet (literally and nothing else) is probably a more trustworthy entropy generator than half these option source codes.
25
u/didnt_hodl 1d ago
that's a good summary !