How do you secure your keys?

Reply to this note

Please Login to reply.

Discussion

I like to have a machine with an OS I trust that never touch internet, then create wallets that I check “watch only” for spending I sign from a virtual machine and not big quantities per wallet. There’s plenty of solutions, for btc I really like many passphrses for the same seed

The keys are stored on your offline machine, on a transaction coordinator?

The best hardware wallet that uses actual hardware: https://www.econoalchemist.com/post/backup

How do you sign a transaction? With something like a seedsigner?

Yup, seedsigner is excellent for this.

Makes sense for this use case 🤝

As for the words on washers method, I like to make it harder for anyone that might gain possession of said hardware by scrambling the numbers that correspond to the words, and using non-English diceware lists.

Interesting. So you have to remember the order the words?

Yes for instance you might reconstruct the actual seed by putting the numbered words in order like so: `2 7 5 6 9 4 10 12 8 1 11 3`.

Hypothetically, lets say someone else has access to your washers, and changes the order, without knowing the purpose of the words. Would that make it harder for you to recover the proper order?

I mean, the numbers are stamped on there to *look* as if they go in normal bip39 defined sequence, afaik I would be the only one that knows I hafta put them in the example `2 7 5 6 9 4 10 12 8 1 11 3` order to properly reconstruct. Prolly not a viable solution for everyone, but I have a thing for remembering number sequences. 🤣

Ah I get it. Only you know the proper sequence. Whatever order the washers are when you collect them, you know how to rearrange them. So there’s a small portion of your seed phrase that is in your mind (the sequence).

Aha! It's pretty trivial to just try all possible combos, but average person that would know what to do with a seed phrase would not go past the "Well I entered this seed and ain't shit here!" phase.

It’s a clever way to create a plausible deniability seed phrase. The answer is in there somewhere, they just have no idea