pull down to refresh
I was going to say, you're basically talking about what vaulting/covenants would add, but with an inferior mechanism.
I personally am not opposed to it in principle as long as recursion is cut out (i.e. you can restrict what your utxo spends to, but not influence the utxo after that through the prior one.) You can still prefabricate a chain of course.
Unfortunately, people burn out on getting this functionality to a point of activation, which also means that it is hard to get the story - as they're burned out - as to what the difficulties truly are.
Note that key loss and even insufficient entropy on a seed can still cause all sorts of trouble so it doesn't solve any of the real problems we have today on its own. You still need good entropy. You still need good key retention and secrecy. You still need to roll keys. You still need to be mindful, actively manage your stack, have watch-only alerts, and hedge everything. So this isn't a silver bullet and it will cause new ways to lose your hard earned stack.
Sorry you mean, my idea is inferior to covenants or vice versa (lol)?
The approach I describe does not have the range of functions etc of a full covenant setup, but we may never get consensus on covenants, and it will take even longer for it to get integrated into wallets.
As of today - It seems for the simple use case of having an emergency failsafe, what I describe works but has not been given much thought or discussion AFAIK.
I don't think it is that much work for someone to presign cold storage UTXOs in Wallet A to Wallet B and keep the file in a safe place "just in case".
I don't understand, covenants don't even exist. What I suggest works today on the protocol and would have helped the guy in the screenshot at the top of the article. Can you clarify your position please?
Like I said, it's a bit of a waste of people's time, but let me be nice and waste my time.
Let's say everyone does this. Attack happens. Everyone now publishes their tx. The first thing that happens is congestion. You don't know what the fee in the future will be especially during congestion. So now you're going to have to do p2a and sign a child tx too in the same go, with the right fee. This means that you have to have at least the anchor device on you, and that needs to be not vulnerable to whatever is going on.
Now, if you're going to have a presigned tx to a place that you carry on you, and a means to trigger said presigned tx, then you still have everything on you and your entire stack is hot. If you presign p2a to a third device with only the anchor on you (see how complicated this is getting?) then now you:
- Have to secure 3 devices.
- Always carry 1 on you.
- Still have an alertness issue.
- Any reactive measure in a key compromise scenario is vulnerable to mempool trickery - just because this attacker was dumb doesn't mean that the next one won't be patient, monitor, RBF race you to 0 (all they can lose is your money, all you can lose is your money) and so on.
- Can be painful with reorgs too. Remember, we'll have 2 chaintips next week, at least for a while. A great attacker times the attack well (this was poor timing, poor execution too.)
- Every other victim is your enemy when this happens, because you'll be competing for a chance to save your stack.
This is why, I think that sure you can do this, but it is not in your interest to standardize it, because it doesn't scale.
PS: it's a bit rich to within 24h complain about LARP and then do it yourself and ask for more LARP.
Forgot to mention that in our corresponce, Lopp reminded me that what I describe above is currently the only feasible way to create any sort of "covenant" functionality in Bitcoin. Somewhat related article on covenants from his company: https://blog.casa.io/why-bitcoin-needs-covenants/