Hey guys,
Do I understand correctly that to use Nunchuk with their platform key as co-signer, you have to sign up with email? That would more or less indirectly tie an identity to the wallet, most likely attached to your phone since you'll have to check email regularly for delay notifications, etc. Add to that the fact that as co-signer they can see your full wallet balance? Iisn't that like putting a big target on your back?
I really like the idea of having one extra key in a setup as an extra backup, but this has a lot of downsides, IMO. Or am I missing something here?
It would actually be great if Nunchuk, Casa, etc. could also adopt the "chain delegation" approach that Bitkey came up with. That could change a lot in terms of privacy if users run on top their own nodes.
What are your thoughts on this?
i don't use nunchuk, so I'm not totally sure, but aside from Bitkey's chain delegation thing, I don't see how you get a cosigner without giving them a lot of visibility. This has definitely kept me from something like a cosigning service. Seems like I'm better off just hunkering down and hiding with my keys on my own.
@nunchuk_io
As far as I understand, chain delegation from Bitkey enables you to be quite private if you know how to set it up (use your own node, disable certain notifications, etc.).
Besides that, in case they have to co-sign, they are able to see this particular transaction (which they claim not to log and want to proof somehow in the future).
Definitely a big upgrade compared to Nunchuk, Casa, etc., which as far as I understand so far can see your whole balance, all movements at any time. I definitely can see many problems in this approach.
So in short, if someone asks Bitkey about your total balance, even if they wanted to, they simply can't tell, while the same for Casa and Nunchuk looks completely different, as they always see your full balance/history, like your bank would.
But maybe I get this wrong? But hard to tell as I wasn't able to find that kind of information in their FAQs etc.
The email address is the only thing required for the service. Can create a dedicated email that does not connect back to your true identity. While balances are visible to them as they hold the platform key this is the trade-off you are making for inheritance purposes. It is a collaborative custody situation by design. You pay them to know your stack and aid your heirs in the event of your death. They can't spend unilaterally because they only hold the one key.
Feels like maybe you are missing the reason for the service.
As far as I understand, the email is quite important, as you would get notifications there that you have to catch in case of a delayed cosign event, etc. Thus, you would usually have to install the app from the mail provider, turn on notifications, etc., and by doing this, link the device to your "identity/location". So, IMO, the moment the Nunchuk database leaks, an "attacker" would see all emails/clients, including their related balances, and then decide if it's worth locating this customer. So, at least to me, this seems like a lot of personal risks added for the purpose of inheritance or simply because you want a kind of other signer in your setup (iron hand plan). All this would be mitigated in big parts, IMO, by adopting chain delegation, etc.
Don't get me wrong, I don't want to talk bad about the product. I personally look to upgrade my multisig after the recent events and came to Nunchuk through this and am evaluating pros/cons now, but for me, if I get it right, at the moment it seems like it would at least for me create more headache than it solves. If they could offer the same service without these issues, which seems technically possible (chain delegation), it would be an easy yes for me, I assume.
Yeah, not only is that possible, it actually happened to me just recently with the CC vulnerability. I have a dedicated account (no kyc) for Nunchuk and I have notifications turned off. I completely missed the email about the platform keys being generated with an MK4... Didn't know about it until I saw someone post about it on X. And the database leak is a risk but again, no KYC, no address, no name. Nothing. So wouldn't really think about that being a concern.
For me, BitKey is just a different set of trade-offs. It's KYC and the hardware is made by a single vendor. Fuck that. Chain Code Delegation is a cool thing that definitely helps with the privacy aspect of collaborative custody but you just give that up when you use BitKey, unless I misunderstand.
Forgive the AI but it's useful here: