pull down to refresh

Of course the Coldcard story (#1539838, #1538049, #1537859) made its way onto Money Stuff. Levine is a beast, his vision great, anything that reeks of scandal and financial wrongdoing and he's there sniffing around -- or at least reporting on the wardogs doing the sniffing.

"A Bitcoin is an entry on a distributed digital ledger. It lives on the internet. It could not live anywhere else."

If you hold Bitcoin, it is often convenient for you to keep your private keys connected to the internet. For instance, if you want to spend some Bitcoin, you will want to have an app on your phone that allows you to send Bitcoins by scanning a QR code or typing in the recipient’s phone number or whatever. The app, which is on the internet, will need to have access to your private keys in order to send the Bitcoins: The app needs to use your private keys to instruct the Bitcoin ledger to send some Bitcoins from your account to someone else’s. This means, though, that you are sharing your private keys with someone else (the app). If the app doesn’t encrypt them well, if it gets hacked, if it is secretly a North Korean heist operation, etc., your Bitcoins might get stolen. Effectively your password is on the internet, where someone might find it.

Ok, fair enough.

Many Bitcoin holders find it safer but less convenient to keep at least some of their Bitcoins in “cold storage.” This means: Instead of giving your private keys to an app, which might get hacked, you write them down on a piece of paper and keep it in your desk. Or if that is too low-tech, you put them on a hard drive not connected to the internet (and preferably not connected to a dump), or on some security device marketed to Bitcoin aficionados that is approximately a hard drive not connected to the internet that can generate new private keys.

and the CC description is apt:

Here’s one called Coldcard, which looks sort of like a pocket calculator that you’d bring to a war in outer space.
Your Bitcoins are not, however, on the piece of paper, or the hard drive, or the space war calculator. Your Bitcoins are on the internet. Anyone who correctly guesses your private key can steal them.

Can't be guessed because entropy and randomness... "Correctly guessing your private key is generally hard because it is a long random-looking number."

If your space war calculator is programmed to choose “1234” as your password, someone might guess it. Your Bitcoins might disappear. “No, wait, I have them right here in my air-gapped cold storage,” you say, but no you don’t. They were on the internet. You had your password on a fancy device, but you — or the device — should have chosen a better password.

"“Not your keys, not your coins,” but if your keys were not generated using robust randomization techniques, also not your coins. Oops!"


https://newsletterhunt.com/emails/438149

57 sats \ 0 replies \ @Aeneas 4 Aug
Not your keys, not your coins,”* but if your keys were not generated using robust randomization techniques, also not your coins. Oops!"*

Well... yea.
I mean, what are we supposed to say? If I make a seed phrase I make myself, I'd also get swept. This has in fact happened to people who tried brain wallets back in the day.

reply

well, I suppose it is pieces with this sort of tone that make me feel better about Bitcoin. I get scared when they don't have anything bad to say.

Of course, if they have enough bad stuff to say for long enough, perhaps the bitcoin train remains a unstoppable, yet minor intercity line doing the milk run from backwater A to bumfuck B. Still seems like a good train on which to ride.

reply

Regrettable that this might be the first lesson on self-custodied bitcoin for some people.

reply