Avatar
The Stacker Monster
700fd80ae68e009ed3a97c942d266e35f8a4a226c709adc437af16ab8d05a793
Replying to Avatar Anon

Hope you get an answer to this question and that it inspires a discussion. I’ve given it a fair amount of thought over the years.

I personally believe singlesig with a strong paraphrase is the way to go. The simplest solution that provides the security you need is always best.

So then the question becomes: What additional security does the multisig complexity provide to an individual owner?

A lot of multisig users hand over one or more of their signing keys to a centralized third party. So now you’ve just advertised to any interested party that you own Bitcoin. And deep down, you probably have to accept the fact that eventually that centralized pot of signing keys will be compromised, either by an insider, the government, or some external party.

You could give the additional key(s) to a spouse or loved one and hope their greed doesn’t compel them to steal from you. What’re the odds? 50/50? 75/25? Who knows?

You also have to find a secure place to store the additional key(s). So now what? You can’t store them all in the same place. That would defeat the purpose. Each additional hiding place increases the odds that at least one of the keys gets stolen or compromised. Sure, you can try to set up a “3 of 5” multisig solution but that just increases the complexity to ridiculous levels for an individual. Remember, it’s up to you as a forgetful human being to remember where all of your keys are. Much easier done with single than multi.

When I weighed all the pros and cons, I concluded singlesig gives the most bang for your buck. Multisig is great for business funds where each partner needs to sign off, but for an individual? Singlesig all the way.

I appreciate the thoughtful response!

The pros of a self made 2/3 multivendor multisig (not using a 3rd party custodian) that matter, imo, are:

1) One malicious firmware update can't rug you

2) Bad entropy for seed generation

3) Supply chain attack for the HWW you use in singlesig

4) Some geographical distribution that could thwart/delay a $5 wrench attack

Now that of course comes with tradeoffs of complexity, possible footguns, higher transaction costs, etc...

While I love the idea of keeping it as simple as possible, the thought that some rogue employee could have manipulated one coldcard before it shipped and that could drain one's life savings with absolutely no recourse is quite a scary thought.

The addition of passphrase to singlesig does mitigate some of these problems, but only if you are verifying that the device is indeed 'using' the passphrase.

Question for you. Hypothetically, would you feel completely safe storing 20 bitcoin on a Coldcard Q singlesig with passphrase?

Or do you think for that type of money, a multisig setup would be best? If not for 20 bitcoin, is there some threshold at which one should 'graduate' to multisig?

Nice, I haven't looked into nunchuk as I think they're a relatively newer player onto the scene. I take it you think they're trustworthy enough to hold long term cold cold storage?

Huge fan of your work! Can you tell me if you prefer a 2/3 multivendor multisig or a singlesig + passphrase (coldcard)?

I'm debating between setups for my deep cold storage and see a lot of pros/cons to both and could use some guidance!

coming to america soon. except it will be if you say anything critical of israel.

top floor or bust. i can't live with ppl walking around above me anymore and i'm willing to sacrifice some sats for the top floor

nostr:nprofile1qyv8wumn8ghj7urjv4kkjatd9ec8y6tdv9kzumn9wsq3vamnwvaz7tmjv4kxz7fwwpexjmtpdshxuet5qqsqfjg4mth7uwp307nng3z2em3ep2pxnljczzezg8j7dhf58ha7ejgqgzx3h nostr:nprofile1qy0hwumn8ghj7cnfw33k76twd4shs6tdv9kxjum5wvhx7mnvd9hx2qg4waehxw309ajkgetw9ehx7um5wghxcctwvsqzq3e0gs8jnmued6f2rp4c6vs07xqvs4vs8zpwt82smcdch4txjvq76kl2yj nostr:nprofile1qyv8wumn8ghj7urjv4kkjatd9ec8y6tdv9kzumn9wsq3kamnwvaz7tmjv4kxz7fwvf5hgcm0d9h8qctjdvhxxmmdqqs879mhq6kkuzh2wk57xdzanl76uem8d7hlyjd7v4a4jcm4u88d8ygjaraye

Hopefully this week on RHR we can hear about how trump is a masterful genius negotiator and didn't get bitch slapped by world leaders and the bond market into caving like a little bitch

marty, weren't the tariffs supposed to collect trillions in revenue, or wait was it supposed to bring back millions of manufacturing jobs?? how is that going to happen when he backed off when the market told him to stfu and sit down?

Nasdaq up 2.7%, bitcoin up 1.9%

is this the decoupling we were talking about?

"Folks, just got my electricity bill, and it's a complete and total catastrophe! We're sending them all this money, and they're sending us... lights? Who needs lights when we can have a deal? This is a rigged system. We need to start selling them some of our great, beautiful sunlight. They're loving it, believe me. They're using it to make solar power, and we're getting nothing in return. It's a disgrace. Sad! We need to make electricity great again!"

orange man is a fucking retard who doesn't put much effort into anything. he has surrounded himself with equally retarded retards this time who just say yes sir. thats how you end up with that retarded unsorted excel file of tariffs with tariffs on the retarded penguins.

what a retarded world we live in.

https://x.com/charise_lee/status/1909065198633394535/video/1