Bitcoin Forum
May 11, 2024, 07:23:42 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Crypto Security - Additional Protection For Your Seed/Private Keys.  (Read 501 times)
madnessteat
Legendary
*
Offline Offline

Activity: 2240
Merit: 2005



View Profile
March 11, 2020, 03:35:49 AM
Merited by JayJuanGee (1)
 #21

Most metal seed phrase storage devices cannot encrypt the seed phrase, which in my opinion is a very important factor. If you store your encrypted seed phrases in more than one cloud storage device it will be much more secure. You can use PGP encryption (https://bitcointalk.org/index.php?topic=4059348.0) and use complex passwords for cloud storage. Even if an attacker can get your encrypted seedphrase, it is almost impossible for them to decrypt it.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
1715455422
Hero Member
*
Offline Offline

Posts: 1715455422

View Profile Personal Message (Offline)

Ignore
1715455422
Reply with quote  #2

1715455422
Report to moderator
1715455422
Hero Member
*
Offline Offline

Posts: 1715455422

View Profile Personal Message (Offline)

Ignore
1715455422
Reply with quote  #2

1715455422
Report to moderator
1715455422
Hero Member
*
Offline Offline

Posts: 1715455422

View Profile Personal Message (Offline)

Ignore
1715455422
Reply with quote  #2

1715455422
Report to moderator
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715455422
Hero Member
*
Offline Offline

Posts: 1715455422

View Profile Personal Message (Offline)

Ignore
1715455422
Reply with quote  #2

1715455422
Report to moderator
nc50lc
Legendary
*
Offline Offline

Activity: 2408
Merit: 5595


Self-proclaimed Genius


View Profile
March 11, 2020, 04:07:26 AM
Merited by bones261 (2), DdmrDdmr (1)
 #22

Most metal seed phrase storage devices cannot encrypt the seed phrase, which in my opinion is a very important factor. If you store your encrypted seed phrases in more than one cloud storage device it will be much more secure. -snip-
I'm pretty sure it can.
The user can always use the standard BIP39 encryption which will only add an additional word to the existing seed (but not to be included to the backup).
Info: BIP-0039

Even if the backup is compromised, the seed will be safe for a while since the mnemonic will derive a different set of keys if there's no passphrase or the correct passphrase wasn't included in the import.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
madnessteat
Legendary
*
Offline Offline

Activity: 2240
Merit: 2005



View Profile
March 11, 2020, 06:02:36 AM
Last edit: March 11, 2020, 09:59:08 AM by madnessteat
 #23

Most metal seed phrase storage devices cannot encrypt the seed phrase, which in my opinion is a very important factor. If you store your encrypted seed phrases in more than one cloud storage device it will be much more secure. -snip-
I'm pretty sure it can.
The user can always use the standard BIP39 encryption which will only add an additional word to the existing seed (but not to be included to the backup).
Info: BIP-0039

Even if the backup is compromised, the seed will be safe for a while since the mnemonic will derive a different set of keys if there's no passphrase or the correct passphrase wasn't included in the import.

I agree that the use of an additional word in the seed phrase is a good solution to increase security damage, but I would recommend having multiple backups available anywhere in the world and anytime.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
Lucius (OP)
Legendary
*
Offline Offline

Activity: 3234
Merit: 5666


Blackjack.fun🎲


View Profile WWW
March 11, 2020, 12:11:19 PM
 #24

I agree that the use of an additional word in the seed phrase is a good solution to increase security damage, but I would recommend having multiple backups available anywhere in the world and anytime.

What is recommended today may become necessary in the future, because if we want security, we have to invest a lot more than $50 in a hardware wallet and 24 words on a regular sheet of paper. As far as I can see, opinions are divided between those who suggest encrypted files saved online or on some medium, and those who still stick with multiple backups on paper/metal plates.

I agree that in case we use backups on paper/metal or any other more durable material, we need to use extra word (passphrase) as extra security in case someone if find our backup. Of course, in this case one should be intelligent and separate the seed words from passphrase, and take into account that weak passphrase is not good move since it is subject to brute force attack.



The whole point of this topic is to start acting more responsibly towards what we are protecting.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18512


View Profile
March 11, 2020, 07:02:14 PM
 #25

I'm pretty sure it can.
Passphrases are great, and everyone should be using one, but they don't encrypt your seed - they are used as a salt for PBKDF2. Your seed is still very much stored in plain text. If you wanted to encrypt your seed phrase and store it on some metal device, then you will need a custom/homemade device. You will need a larger character set than just 26 capital letters, and far more of them, than these commercial products can accommodate.

As far as I can see, opinions are divided between those who suggest encrypted files saved online or on some medium, and those who still stick with multiple backups on paper/metal plates.
I use paper back ups, hardware wallets, and encrypted files, but I would advise against storing anything online. Even if it is encrypted, are you 100% confident in the encryption software you used? Are you 100% sure you left no traces of the unencrypted file on your internet enabled device? Are you 100% sure your encryption key is 100% secure and will never be broken? Why take an unnecessary risk? Just store it on a USB drive or airgapped device.
nc50lc
Legendary
*
Offline Offline

Activity: 2408
Merit: 5595


Self-proclaimed Genius


View Profile
March 12, 2020, 03:40:20 AM
Merited by o_e_l_e_o (1)
 #26

I'm pretty sure it can.
Passphrases are great, and everyone should be using one, but they don't encrypt your seed - they are used as a salt for PBKDF2. -snip-
Yeah, it makes sense, you cannot reverse PBKDF2 so it isn't encryption.
But every Wiki/Article link about BIP39's passphrase labels it as "encryption" simply because it uses a "passphrase", those need some correction.

For the security, it's not that safe as I mentioned earlier: "the seed will be safe for a while" (the seed, not mnemonic).

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!