Bitcoin Forum
April 25, 2024, 06:16:54 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Coinplate Steel Seed Phrase Saver  (Read 831 times)
Pmalek
Legendary
*
Offline Offline

Activity: 2744
Merit: 7095



View Profile
September 10, 2022, 07:37:20 AM
 #21

@foggoat
Can these units be shipped to PO boxes and how do you handle private information of your clients?
Is it deleted and wiped altogether from servers, how long is it stored, and do you self-store data or rely on a 3rd-party?

Hacking or leaking information about thousands of users who have ordered steel plates could be a valuable piece of info and a dangerous hit list of sorts. Not just from your company, but in general.   

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
Even if you use Bitcoin through Tor, the way transactions are handled by the network makes anonymity difficult to achieve. Do not expect your transactions to be anonymous unless you really know what you're doing.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
1714025814
Hero Member
*
Offline Offline

Posts: 1714025814

View Profile Personal Message (Offline)

Ignore
1714025814
Reply with quote  #2

1714025814
Report to moderator
n0nce
Hero Member
*****
Offline Offline

Activity: 882
Merit: 5814


not your keys, not your coins!


View Profile WWW
September 10, 2022, 11:47:12 PM
Merited by Pmalek (1)
 #22

In my locality, there is no store that has it, so I ordered it from online shipping which costed me $276.00 because of the distance of my country, that is excluding the shipping fees. The additional shipping fees of $50 was added and the total cost is $326.00.

https://getcoinplate.com/product/coinplate-alpha/
Quote
Coinplate Alpha
$ 79.00 – $ 276.00 incl. tax
This is the price in the website. The shipping fee down to my community is high within my country and this will come from outside country. So I only add $50 for the $276.00 base in the distance though that might be wrong from the calculation.
The problem is that $276.00 is for 5 plates and you made it seem like you paid that amount for a single one.
And it was confirmed that shipping is FREE worldwide above $100; you can't just come up with a random figure - and say that you paid $50 on top of the $276.00, as that's impossible even if you got the 5-pack.

FREE WORLDWIDE SHIPPING ON ORDERS OVER $100 /€

Especially this quote ('costed' - by the way: isn't past tense of 'cost', also 'cost'?) makes it seem like you already ordered and paid for it. You obviously haven't, otherwise you'd know the real price for 1 of these including shipping.
In my locality, there is no store that has it, so I ordered it from online shipping which costed me $276.00 because of the distance of my country, that is excluding the shipping fees. The additional shipping fees of $50 was added and the total cost is $326.00.

Sorry that I'm getting mad, I just hate misinformation.



I just played around with the country selection, and if you get a single plate (under 100€), then shipping to some African states (haven't tested all of them) is 19€. You don't have to leak your location of course, but I just think $50 shipping for one plate is too expensive and just doesn't make sense / wouldn't be offered, if you can get e.g. a 3-pack for 189€ and have free shipping.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
foggoat
Newbie
*
Offline Offline

Activity: 16
Merit: 68


View Profile WWW
September 11, 2022, 01:26:40 PM
 #23

@foggoat
Can these units be shipped to PO boxes and how do you handle private information of your clients?
Is it deleted and wiped altogether from servers, how long is it stored, and do you self-store data or rely on a 3rd-party?

Hacking or leaking information about thousands of users who have ordered steel plates could be a valuable piece of info and a dangerous hit list of sorts. Not just from your company, but in general.  

About PO Boxes, we currently ship to post boxes that are freely accessed by third-party delivery companies like FedEx. This mostly includes mailboxes or virtual mailboxes that are operated by some 3rd party private companies. For the moment we might be unable to deliver to some post boxes that are operated by post operators like USPS in the USA, as they don't allow other operators to access them.  If you think this is something that might be desirable by some customers, I think we can look into adding international post/mail delivery, which should be able to reach regular post boxes. For most folks, it would be not an ideal option, but maybe for PO Box delivery, it would be beneficial.


Regarding the data. I am aware that data security is an important thing. We are not that big but we do take some measures to secure the data.
Currently, we offer everyone (not just EU-based customers) to ask for full erasure of their personal data and transaction details after the return period is over. A significant % of our customers ask us to do so right in the order form. This includes all data on our servers as well as all e-mail messages.
As an EU-based company, we are obliged to follow strict GPDR law, that requires us to delete all your data on your request. Also, it allows us to request the same on behalf of our customer to third parties like payment processors and delivery companies, which we do as well. We don't keep data at 3rd parties aside from our servers. Also we purge the database manually every few months, as I don't like the idea of hoarding the customers data indefinitely.
The only data that remains at us then are obligatory tax records i.e. receipts but we move them to offline and/or paper storage periodically which is kept in a separate physical location.
 
I am looking into making this process fully automatic which will allow us to, by default, delete everyone's data after 30 days from the delivery. It involves some work so it will take some time to implement, privacy policy needs some legal work too. We'll announce when it's ready. Probably then if someone opted in for a newsletter or sth we will just keep their e-mail address but nothing else.

Open to all suggestions for improving the data security.


Though if just your own house burns down (not a huge apocalyptic sized fire), you should have redundant seed phrase backups elsewhere.


That's right. What I might recommend is to have your seed splitted in 2/3 way, which means you can read your seed while having any 2 out of 3 copies. Yet with only one of copies you cannot get the seed as it will require you to crack 8/24 of seed which still will take at best months if not few years. This requires having 3 safe locations, possibly different physical addresses. You should have them in a place where you can check each few months if it was untouched, for total peace of mind. It's easy to do, but If you need details I can give you some instructions if you PM me. I'll probably make a tutorial at our site in the future too.


I just played around with the country selection, and if you get a single plate (under 100€), then shipping to some African states (haven't tested all of them) is 19€. You don't have to leak your location of course, but I just think $50 shipping for one plate is too expensive and just doesn't make sense / wouldn't be offered, if you can get e.g. a 3-pack for 189€ and have free shipping.

Forgot to add previously that shipping to some remote or expensive locations is $19 instead of regular $9. Edited the original reply accordingly. This includes countries like Autralia, New Zealand, islands in the middle of the sea, Switzerland, Norway, some African and Asian countries. You can get the delivery price from the product page or checkout. Still it is free for orders everywhere over $100 like you just pointed out.

Please be aware that in some countries you can get charged by local customs office import tarriffs, tax or duties at delivery. We listed info about some most popular destinations at our site, but in other cases you should check how it looks like with your local customs office. Maybe that's what the OP, Agbe meant? I believe it could add up to $50 with $270 value in some cases.


Also it might be important to some folks here, especially in US market, that all prices at our site include all sales taxes so the prices = amount paid.
Pmalek
Legendary
*
Offline Offline

Activity: 2744
Merit: 7095



View Profile
September 12, 2022, 08:04:11 AM
 #24

That's right. What I might recommend is to have your seed splitted in 2/3 way, which means you can read your seed while having any 2 out of 3 copies. Yet with only one of copies you cannot get the seed as it will require you to crack 8/24 of seed which still will take at best months if not few years. This requires having 3 safe locations, possibly different physical addresses. You should have them in a place where you can check each few months if it was untouched, for total peace of mind. It's easy to do, but If you need details I can give you some instructions if you PM me. I'll probably make a tutorial at our site in the future too.
Sounds like you are talking about Shamir's Secret Sharing. The problem with SSS is its single point of failure. The splitting part is done on a single device and the reconstruction of the shares is also done on one device. That's the single point of failure. Jameson Lopp talks about it in detail here. A standard 2/3 multisig setup sounds like a better idea.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
foggoat
Newbie
*
Offline Offline

Activity: 16
Merit: 68


View Profile WWW
September 12, 2022, 11:31:26 AM
Merited by xandry (4)
 #25

That's right. What I might recommend is to have your seed splitted in 2/3 way, which means you can read your seed while having any 2 out of 3 copies. Yet with only one of copies you cannot get the seed as it will require you to crack 8/24 of seed which still will take at best months if not few years. This requires having 3 safe locations, possibly different physical addresses. You should have them in a place where you can check each few months if it was untouched, for total peace of mind. It's easy to do, but If you need details I can give you some instructions if you PM me. I'll probably make a tutorial at our site in the future too.
Sounds like you are talking about Shamir's Secret Sharing. The problem with SSS is its single point of failure. The splitting part is done on a single device and the reconstruction of the shares is also done on one device. That's the single point of failure. Jameson Lopp talks about it in detail here. A standard 2/3 multisig setup sounds like a better idea.
I didn't mean Shamir's Secret Sharing, it's probably too complicated for most of ppl including myself. Not a biggest fan of multisig, but it might be nice if you have a big holdings.

I meant just very simple idea that you just split your seed into thirds. Then each copy has 2/3 of the full seed on itself. You just do it manually, no tech no math approach. For example 1st copy has words 1-16th, 2nd has 9-24th and 3rd has 1-8th + 17-24th. I think that it's simple and it works, it might be good enough for most long term hodlers.
n0nce
Hero Member
*****
Offline Offline

Activity: 882
Merit: 5814


not your keys, not your coins!


View Profile WWW
September 12, 2022, 11:33:32 AM
Merited by xandry (4)
 #26

That's right. What I might recommend is to have your seed splitted in 2/3 way, which means you can read your seed while having any 2 out of 3 copies. Yet with only one of copies you cannot get the seed as it will require you to crack 8/24 of seed which still will take at best months if not few years. This requires having 3 safe locations, possibly different physical addresses. You should have them in a place where you can check each few months if it was untouched, for total peace of mind. It's easy to do, but If you need details I can give you some instructions if you PM me. I'll probably make a tutorial at our site in the future too.
Sounds like you are talking about Shamir's Secret Sharing. The problem with SSS is its single point of failure. The splitting part is done on a single device and the reconstruction of the shares is also done on one device. That's the single point of failure. Jameson Lopp talks about it in detail here. A standard 2/3 multisig setup sounds like a better idea.
I'd also advocate for Multisig instead of SSS. It was discussed on this forum at length, a whole bunch of times and if memory serves correct, Multisig always came out on top.

Even Gregory Maxwell himself seems to agree with this:
[...]
It is my view that In general, secret sharing is largely snake oil in practice because you must have a computer to split and join keys and if that computer is compromised your security is gone.  If you really had a compromise immune computer, just leave your key there and avoid the pointless ritual.

Bitcoin has multisignature which allows split keys without any single point of failure. Anyone considering secret sharing should first have a darn good reason they aren't using multisig.
[emphasis mine]

I didn't mean Shamir's Secret Sharing, it's probably too complicated for most of ppl including myself. Not a biggest fan of multisig, but it might be nice if you have a big holdings. I meant just very simple idea that you just split your seed into thirds. Then each copy has 2/3 of the full seed on itself. You just do it manually, low or no tech approach. For example 1st copy has words 1-16th, 2nd has 9-24th and 3rd has 1-8th + 17-24th. I think that it's simple and it works, it might be good enough for most long term hodlers.
That's actually even worse! If you lose 1 part, the whole thing's gone. Never do that!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
foggoat
Newbie
*
Offline Offline

Activity: 16
Merit: 68


View Profile WWW
September 12, 2022, 11:38:29 AM
 #27


That's actually even worse! If you lose 1 part, the whole thing's gone. Never do that!

Have you even taken a minute to think about it or just straight assumed it's wrong? The thing is it's a 2 out of 3 scheme, you need to lose 2 parts out of 3 to lose your seed phrase. If you lose just 1 part out of 3 you are safe and sound.
n0nce
Hero Member
*****
Offline Offline

Activity: 882
Merit: 5814


not your keys, not your coins!


View Profile WWW
September 12, 2022, 11:46:06 AM
Merited by xandry (4)
 #28


That's actually even worse! If you lose 1 part, the whole thing's gone. Never do that!

Have you even taken a minute to think about it or just straight assumed it's wrong? The thing is it's a 2 out of 3 scheme, you need to lose 2 parts out of 3 to lose your seed phrase.
Sorry; misread. I thought you'd recommend splitting 1-8, 9-16, 17-24.

Anyone considering secret sharing should first have a darn good reason they aren't using multisig.
As gmaxwell said, though, I don't understand why. There are so many good guides for setting up Multisig with basically any software and hardware wallet and combination of them.
A nice side effect is that you can deposit dummy amounts on each individual seed to deter any thief / finder to go looking for a second seed.

And also.. it just works, it's integrated into wallets and it's a popular scheme, so if someone has a problem with setup or restore, they'll find help online without a problem.
I can almost guarantee that they would find less users who know about this '1-16, 9-24, 1-8 + 17-24' scheme and who will be able to assist.



I haven't calculated it with 24 words, but it appears that if someone found 2/3 of the words of a 12-word seed phrase (8 words), it's possible to crack the remaining 4 words rather quickly.
https://bitcoin.stackexchange.com/a/101336/119879

Basically, in your scheme, each share holds 2/3 of the original seed's key material.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
foggoat
Newbie
*
Offline Offline

Activity: 16
Merit: 68


View Profile WWW
September 12, 2022, 01:06:23 PM
Merited by xandry (4)
 #29


That's actually even worse! If you lose 1 part, the whole thing's gone. Never do that!

Have you even taken a minute to think about it or just straight assumed it's wrong? The thing is it's a 2 out of 3 scheme, you need to lose 2 parts out of 3 to lose your seed phrase.
Sorry; misread. I thought you'd recommend splitting 1-8, 9-16, 17-24.


No problem, that would be dumb. No one should straight split their seed, I agree.

Anyone considering secret sharing should first have a darn good reason they aren't using multisig.
As gmaxwell said, though, I don't understand why. There are so many good guides for setting up Multisig with basically any software and hardware wallet and combination of them.
A nice side effect is that you can deposit dummy amounts on each individual seed to deter any thief / finder to go looking for a second seed.

And also.. it just works, it's integrated into wallets and it's a popular scheme, so if someone has a problem with setup or restore, they'll find help online without a problem.
I can almost guarantee that they would find less users who know about this '1-16, 9-24, 1-8 + 17-24' scheme and who will be able to assist.

The multisig is a solid approach, I cannot argue with that. Not meant it to be a multisig alternative, but as a whole Multisig is still more complicated than the simple approach I suggested. The scheme I suggested can be explained in a few sentences and solid, durable backups are easy to make. However, multisig needs a detailed tutorial and compatible wallets. It might be difficult to remember it all after a few years or if your family member would ever need to access your coins.  

Most importantly, the discussion started from just simply keeping the extra backups of your seed phrase, not making it totally hackerproof or other things if I recall correctly.
Though if just your own house burns down (not a huge apocalyptic sized fire), you should have redundant seed phrase backups elsewhere.

If you were to keep just 3 straight backups of your seed phrase in separate locations, you will be better off using the scheme I suggested. In the thing, I suggested If someone found one of your backups you will be safe from hacking for quite some time (at least a few months if not years), it will require some proper knowledge and resources (incl. time) to crack it. Furthermore, I haven't mentioned this idea as any sort of alternative to a multisig, as it's a whole different beast altogether, and I don't really follow why we are discussing it that way.


And also.. it just works, it's integrated into wallets and it's a popular scheme, so if someone has a problem with setup or restore, they'll find help online without a problem.
I can almost guarantee that they would find less users who know about this '1-16, 9-24, 1-8 + 17-24' scheme and who will be able to assist.
Probably, true. However, the approach I suggested is quite simple so probably no true need for a lot of explainers. As mentioned earlier multisig is still a more complicated thing.


I haven't calculated it with 24 words, but it appears that if someone found 2/3 of the words of a 12-word seed phrase (8 words), it's possible to crack the remaining 4 words rather quickly.
https://bitcoin.stackexchange.com/a/101336/119879

Basically, in your scheme, each share holds 2/3 of the original seed's key material.

Honestly, I haven't thought that someone might still make a wallet with 12 words nowadays, it's not a good practice. I mentioned 24th words seed in my example.
Cracking 4 words of BIP39 seed is hardly comparable to cracking 8 words. To crack 4 words you need around 2^40 combinations, for 8 words it's around 2^80, it's a completely different thing. (not really precise math here though) You will have 7 words to crack on one of the backups as the last word is a checksum, but it's not that much difference.
It will take quite a lot of knowledge and computing power +money  to crack 8 words and it still will take months if not years. Also they will need to get one of your backups in their hands first.  

And as we were discussing just a mere alternative way of keeping your multiple seed backups in different locations, I think that's quite good for something that is so easy to do.
Even for 12th words (which is not ideal) it still beats keeping multiple backups straight and fully, as it requires proper knowledge to crack even 3 or 4 words. A bit harder to do than just putting the words into a wallet.  Overall multisig will offer probably much better security, but a bit more complicated to do properly.

I am not arguing that one is better than the other, though. I'm not pushing anyone to use that scheme. Different things for different folks. Never meant it as an alternative to multisig. Just replying to your arguments.

It is a simple no-tech idea meant as a way for keeping multiple seed backups in separate physical locations, where you are not able to keep an eye on all of them for 24/7.  

This is quite a digression from the main topic and maybe it would be best to not make this the center of this thread and avoid jumping into this rabbit hole.
n0nce
Hero Member
*****
Offline Offline

Activity: 882
Merit: 5814


not your keys, not your coins!


View Profile WWW
September 12, 2022, 01:56:13 PM
 #30

Most importantly, the discussion started from just simply keeping the extra backups of your seed phrase, not making it totally hackerproof or other things if I recall correctly.
Though if just your own house burns down (not a huge apocalyptic sized fire), you should have redundant seed phrase backups elsewhere.
If you were to keep just 3 straight backups of your seed phrase in separate locations, you will be better off using the scheme I suggested.
True; I got sidetracked a little bit. Wink I guess both have their benefits and drawbacks. 3 full seed backups means almost guaranteed not to lose funds, while not being hackerproof at all.
Your method would be more secure against an attacker / if someone found one backup, however the owner may lose 2 backups and lose all their funds or they could forget how the scheme worked and not be able to recover it.

And as we were discussing just a mere alternative way of keeping your multiple seed backups in different locations, I think that's quite good for something that is so easy to do.
Even for 12th words (which is not ideal) it still beats keeping multiple backups straight and fully, as it requires proper knowledge to crack even 3 or 4 words. A bit harder to do than just putting the words into a wallet.  Overall multisig will offer probably much better security, but a bit more complicated to do properly.

I am not arguing that one is better than the other, though. I'm not pushing anyone to use that scheme. Different things for different folks. Never meant it as an alternative to multisig. Just replying to your arguments.
The reason why me and others 'quickly' bring up multisig is that it's less hard / scary to set up and use as some may believe & it's popular; you can see in this forum alone how from time to time people come in asking for help with their custom-seed-backup that they can't restore anymore.

No worries! Just want to make sure before you recommend custom backup schemes to customers that they are aware that we already have tried, tested, documented and popular schemes (maybe a little more effort to set up) that they could have an easier time recovering, years down the line. If not just because they are more common.

It is a simple no-tech idea meant as a way for keeping multiple seed backups in separate physical locations, where you are not able to keep an eye on all of them for 24/7.
This is quite a digression from the main topic and maybe it would be best to not make this the center of this thread and avoid jumping into this rabbit hole.
Sorry about the off-topic!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pmalek
Legendary
*
Offline Offline

Activity: 2744
Merit: 7095



View Profile
September 12, 2022, 04:45:23 PM
 #31

I read your replies and I understand you are just suggesting an alternative and not saying that it's better than this or that. I like this video of Andreas Antonopoulos who explains why seed splitting is a bad idea: Bitcoin Q&A: Why is Seed Splitting a Bad Idea?

His exact words is that the suggested splitting method is absolutely not safe and that people should never make such custom shares and store them separately. He does go on to suggest that SSS is a better solution than custom-made splits because if you have less words than the needed quorum in SSS, its like you don't have any words at all. But having knowledge of 16 words like in your example makes it exponentially easier to bruteforce the remaining 7 or 8. 7 because the last word is a checksum, so it's easier to guess that one. Andreas also suggests that in the next decade, it should be possible to bruteforce 7-8 words with powerful-enough machines.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
foggoat
Newbie
*
Offline Offline

Activity: 16
Merit: 68


View Profile WWW
September 12, 2022, 06:23:31 PM
 #32

OFFTOPIC
I read your replies and I understand you are just suggesting an alternative and not saying that it's better than this or that. I like this video of Andreas Antonopoulos who explains why seed splitting is a bad idea: Bitcoin Q&A: Why is Seed Splitting a Bad Idea?

His exact words is that the suggested splitting method is absolutely not safe and that people should never make such custom shares and store them separately. He does go on to suggest that SSS is a better solution than custom-made splits because if you have less words than the needed quorum in SSS, its like you don't have any words at all. But having knowledge of 16 words like in your example makes it exponentially easier to bruteforce the remaining 7 or 8. 7 because the last word is a checksum, so it's easier to guess that one. Andreas also suggests that in the next decade, it should be possible to bruteforce 7-8 words with powerful-enough machines.
I absolutely disagree with his explanation and his recommendations. You can check the comments to see that he couldn't really prove his point in that video. Also, I think that you miss the entire point here. I'll stop at that as it's not the topic here...
m2017
Legendary
*
Offline Offline

Activity: 1792
Merit: 1299


keep walking, Johnnie


View Profile
September 14, 2022, 10:39:15 AM
Merited by fillippone (2)
 #33

That's right. What I might recommend is to have your seed splitted in 2/3 way, which means you can read your seed while having any 2 out of 3 copies. Yet with only one of copies you cannot get the seed as it will require you to crack 8/24 of seed which still will take at best months if not few years. This requires having 3 safe locations, possibly different physical addresses. You should have them in a place where you can check each few months if it was untouched, for total peace of mind. It's easy to do, but If you need details I can give you some instructions if you PM me. I'll probably make a tutorial at our site in the future too.
Ok. You suggest splitting seed phrasee into 3 parts and storing it in 3 different places. It turns out, 8 words for each coinplate. Then it would be right to add mini-coinplate (like coinplate split - I don't need thanks for the name I came up with for your new product line Smiley) to the assortment of your store. A smaller version of coinplate with space for 8 words and offer them in packs of 3 (for 1 to 8, 9 to 16, 17 to 24 words).

I don't undertake to discuss the correctness of dividing splitting seed into 3 parts, since, for example, Pmalek believes that this is a bad idea (not only he thinks so).
~snip
Let's leave the right to choose exactly how to store their seed phrase, splited or whole for the owners of it personally.

I want to say the following. If foggoat voices this method, then it would be logical to offer his customers to purchase a product that allows you to split seed into 3 parts. Those samples that are available in the https://getcoinplate.com/ are not suitable for this (it contain space for 24 words) and buying 3 coinplates to fill only ~30% of the surface of each I consider wasteful. In total, 3 such plates will cost ~200-240 euro (Punch version or Alpha). Offer buyers 3 mini-coinplates for 8 words for the approximate price of one coinplate (~70-80 euro). Then this will be useful, otherwise it turns out that you offer this method of spliting seed into 3 parts only in order to increase your sales (selling 3 plates is better than 1, right). No offense. I expressed my subjective opinion.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pmalek
Legendary
*
Offline Offline

Activity: 2744
Merit: 7095



View Profile
September 14, 2022, 03:47:36 PM
 #34

Ok. You suggest splitting seed phrasee into 3 parts and storing it in 3 different places. It turns out, 8 words for each coinplate. Then it would be right to add mini-coinplate (like coinplate split
It's not 8 words per seed plate, it's 16 words per seed plate. 8 words in total are missing from each share. No matter which two shares you have, you will have all the necessary words to restore your wallet.

I don't undertake to discuss the correctness of dividing splitting seed into 3 parts, since, for example, Pmalek believes that this is a bad idea (not only he thinks so).
I agree with Andreas in the sense that a seed shouldn't be split up because losing one part can create plenty of difficulties. In this particular example, losing one split wouldn't do that because you still have two remaining. And any 2 out of 2 shares are enough for wallet recovery. I am not sure what you can do with today's technology and how far we are from being able to bruteforce 7 or 8 words. But no matter how easy or difficult it is, bruteforcing 8/24 is exponentially faster than cracking all 24.

foggoat method isn't bad in the sense that it's ridiculous. It isn't. If you split your seed in the way he suggested and someone finds one of your backups, he would have 16 out of 24 words needed to steal the coins. If you have 3 different backups with all your words written down on all 3 pieces of paper and one of them got stolen, the thief would have everything they need to get to your coins. In that sense, it would have been better to use foggoat's splitting system.

But why give a thief even 16 out of 24 words if you can do it in a better way? With SSS, finding a share that is below a quorum, is like having found nothing at all. Even better, finding 1/3 of a 2/3 multisig gets you no closer to the coins because you need 2/3 to spend the BTC. 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3248
Merit: 4110


View Profile
September 15, 2022, 12:08:37 PM
Merited by Pmalek (2), n0nce (1)
 #35

That's some serious density and heat resistance!

While I'm still a big fan of the 'DIY washer method' (there's no metal seed phrase backup, remotely as cheap) - since a coinplate does not cost $300 USD, I may consider it in the future for a very 'heavy' (packed with good amount of coins) Bitcoin wallet.
Though if just your own house burns down (not a huge apocalyptic sized fire), you should have redundant seed phrase backups elsewhere.

Buried under the basement / in the cement sounds like a good idea.
Yeah, your house footings even if it was a fire or what not probably aren't going anywhere any time soon, so cementing in concrete is a decent idea. Plus, no one's going to be digging that up while you're there, unless someone pulls some Prison Break esque plan on you, but that's incredibly unlikely.

However, while it's nice that this product exists, and I know the costs have been figured out a little more since the OP, I can't help, but think I could just go to my local metal works shop, and get something of similar quality for much less, and wouldn't need to ship it. Obviously, you could argue that your local metal works could be using lesser metal, but you could potentially test it yourself to assure that. So, this product is decent for those that can't find any other means, but it's still rather expensive when you factor in almost everyone has access to this sort of thing locally at a reduced cost.
m2017
Legendary
*
Offline Offline

Activity: 1792
Merit: 1299


keep walking, Johnnie


View Profile
September 15, 2022, 04:29:16 PM
 #36

That's some serious density and heat resistance!

While I'm still a big fan of the 'DIY washer method' (there's no metal seed phrase backup, remotely as cheap) - since a coinplate does not cost $300 USD, I may consider it in the future for a very 'heavy' (packed with good amount of coins) Bitcoin wallet.
Though if just your own house burns down (not a huge apocalyptic sized fire), you should have redundant seed phrase backups elsewhere.

Buried under the basement / in the cement sounds like a good idea.
Yeah, your house footings even if it was a fire or what not probably aren't going anywhere any time soon, so cementing in concrete is a decent idea. Plus, no one's going to be digging that up while you're there, unless someone pulls some Prison Break esque plan on you, but that's incredibly unlikely.

However, while it's nice that this product exists, and I know the costs have been figured out a little more since the OP, I can't help, but think I could just go to my local metal works shop, and get something of similar quality for much less, and wouldn't need to ship it. Obviously, you could argue that your local metal works could be using lesser metal, but you could potentially test it yourself to assure that. So, this product is decent for those that can't find any other means, but it's still rather expensive when you factor in almost everyone has access to this sort of thing locally at a reduced cost.
For any product there is always a buyer. Accordingly, there is a corresponding demand for products, such as coinplate, even at declared prices. For people like you, who are able to make an coinplate's equivalent with the tools and materials at hand from the nearest shop, coinplate seems overpriced. But it should be borne in mind that not everyone has such skills and the desire to actually make seed phrase saver like coinplate by hands. It seems to me that the coinplate and analogues of other competitors are aimed at such buyers. I almost forgot to point out that they are also ready to expect delivery (buying locally is incomparably faster) and neglecting the safety of personal data, such as payment details (if you pay not in cryptocurrency) and delivery address. Buying locally leaves no "trace" that you bought the coinplate and respectively, you are the crypto owner.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
n0nce
Hero Member
*****
Offline Offline

Activity: 882
Merit: 5814


not your keys, not your coins!


View Profile WWW
September 15, 2022, 10:16:26 PM
Merited by Pmalek (2)
 #37

However, while it's nice that this product exists, and I know the costs have been figured out a little more since the OP, I can't help, but think I could just go to my local metal works shop, and get something of similar quality for much less, and wouldn't need to ship it. Obviously, you could argue that your local metal works could be using lesser metal, but you could potentially test it yourself to assure that. So, this product is decent for those that can't find any other means, but it's still rather expensive when you factor in almost everyone has access to this sort of thing locally at a reduced cost.
Shipping physical, clearly Bitcoin-related products (and other goods, too) is always an area of concern.
Price-wise though, I just checked and their markup is actually not too high, considering the extra work for the milling, tapping and engraving. Though if you don't need that, you can get away a good chunk cheaper by getting the steel cut locally.

Coinplate:
Quote
The Plate size: 13.8 x 10.5 cm
The Plate Thickness: 5mm | 3/16″
The Material: 100% Stainless Steel, type: 1.4301 | AISI 304
Price: $79 USD

Random piece of AISI 304 on a general metal store (probably similar to local hardware store prices):
Quote
Size: 12.7 x 10.16cm
Thickness: 5mm
Price: $32 USD



█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Welsh
Staff
Legendary
*
Offline Offline

Activity: 3248
Merit: 4110


View Profile
September 15, 2022, 11:52:35 PM
 #38

For any product there is always a buyer. Accordingly, there is a corresponding demand for products, such as coinplate, even at declared prices. For people like you, who are able to make an coinplate's equivalent with the tools and materials at hand from the nearest shop, coinplate seems overpriced. But it should be borne in mind that not everyone has such skills and the desire to actually make seed phrase saver like coinplate by hands. It seems to me that the coinplate and analogues of other competitors are aimed at such buyers. I almost forgot to point out that they are also ready to expect delivery (buying locally is incomparably faster) and neglecting the safety of personal data, such as payment details (if you pay not in cryptocurrency) and delivery address. Buying locally leaves no "trace" that you bought the coinplate and respectively, you are the crypto owner.
Yeah, don't get me wrong here. I'm not criticising that they're doing this (I quite like that these type of services/products exist), I'm just suggesting those that are willing will find easier ways of going about this, with less security risks, and more convenience. The security risks aren't all that much as has already been discussed, for example using PO boxes for both security, and privacy is probably wise.

As suggested above their markup isn't crazy, and does save you some of the effort yourself, so definitely the local metal works route is definitely for the Do It Yourself (DIY) type of people.
dkbit98
Legendary
*
Offline Offline

Activity: 2212
Merit: 7068


Cashback 15%


View Profile WWW
September 16, 2022, 01:08:29 PM
 #39

I absolutely disagree with his explanation and his recommendations. You can check the comments to see that he couldn't really prove his point in that video. Also, I think that you miss the entire point here. I'll stop at that as it's not the topic here...
Problem I see with splitting seed phrases in any other way than good multisig setup, is that you will have single point of failure.
Losing single part of split seed words would mean you will lose all your coins and all other parts would be useless.
I could say similar thing for Shamir Secret Sharing, it also has single point of failure.

Yeah, your house footings even if it was a fire or what not probably aren't going anywhere any time soon, so cementing in concrete is a decent idea. Plus, no one's going to be digging that up while you're there, unless someone pulls some Prison Break esque plan on you, but that's incredibly unlikely.
All they need is metal detector to see if something is hidden inside walls or floor, so I think this could be main negative side of using any metal based seed words backup.
I am not saying someone would scan for seed words with metal detectors, but they could used them to scan for other precious metals, so this this would be biproduct.

Shipping physical, clearly Bitcoin-related products (and other goods, too) is always an area of concern.
Price-wise though, I just checked and their markup is actually not too high, considering the extra work for the milling, tapping and engraving.
It's much less dangerous than buying hardware wallets, since this is just a piece of metal and there is no direct connection with Bitcoin.
You could probably ask them to write on declaration paper it's just a metal plate for home use.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
DaveF
Legendary
*
Offline Offline

Activity: 3458
Merit: 6234


Crypto Swap Exchange


View Profile WWW
September 16, 2022, 04:51:23 PM
 #40

Yeah, your house footings even if it was a fire or what not probably aren't going anywhere any time soon, so cementing in concrete is a decent idea. Plus, no one's going to be digging that up while you're there, unless someone pulls some Prison Break esque plan on you, but that's incredibly unlikely.
All they need is metal detector to see if something is hidden inside walls or floor, so I think this could be main negative side of using any metal based seed words backup.
I am not saying someone would scan for seed words with metal detectors, but they could used them to scan for other precious metals, so this this would be biproduct.

Drifting way OT, but in a lot of new construction you see metal mending / binding plates where 2 pieces of lumber meet:

https://www.homedepot.com/b/Building-Materials-Building-Hardware-Mending-Plates/Prong-Plate/N-5yc1vZasc4Z1z1at5c

Nail them together and then use these for more support so metal that can be found with a metal detector in walls is not a big deal in a lot of locations.
With that being said I think in most locations a piece of metal like this is going to be unnoticed.

Which is more obvious, something like a seed place or hardware wallet sitting in a safe or a seed plate screwed to the underside of a couch so that it looks like someone did a quick and dirty repair?
Which I may done with a normal piece of metal I found.

Makes you wonder if someone could make a seed plate that is 'aged' to look like a piece of junk metal that has been sitting around since before the home PC existed, never-mind BTC

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!