I don't get the point of 3. what's to stop whoever created a session from reusing it? The idea of a "session" is that there is a clear way to close/revoke the session.
By session I mean a temporary key for that particular signing day.
I am thinking of a situation where you have to travel to collect fragments. Once you have used them, you have to travel to bring them back.
Just copying the fragment would fix that, so maybe I am overthinking things.
In retrospect, the low tech solution is best. All you need is a pen and paper.
I was thinking risk of theft or destruction during transit, but the stored fragment isn't sufficient to release the funds on its own and the original paper backup is still back at the safe location.
As the price rises, the level of professionalism in securing the fragments increases.
Ideally, people should put the security in place before they have a significant fraction of their wealth in cryptocurrency.
There are 3 main types of risk
- theft
- extortion
- destruction
Armory is mainly targeted at protecting against destruction and electronic theft.
The primary point of fragments is to protect against destruction of the seed by placing them in multiple locations. This can include destruction by forgetting the seed.
If the fragments are in multiple locations, then more than one must be destroyed simultaneously.
It also protects against opportunistic thefts. If someone happens to steal one fragment, it is worthless.
The risk model in the early days was that forgetting your password was vastly more likely than physical theft. Is that still true with rising valuations?
A safe deposit box gives protection against extortion risk. Telling someone where the fragment is doesn't help them.
There is a tension between redundancy and extortion risk.
If you have a safe deposit box, then that protects against extortion only if the fragment in the safe deposit box is required to release the funds (so N of N).
If that condition is met, then it removes the redundancy. Damage to the paper backup in the safe deposit box means all funds are lost.
Maybe the solution is to have 2 safe deposit boxes. They are only a few hundred dollars a year.