Except this isn't even remotely true! This is the sloppiest and most scammy financial institution that I've ever interacted with. They claim to abide by KYC guidelines then happily ignore your identity when you come to recover the account they gleefully have locked you out of. Every user, on a long enough timeline, will experience some kind of lockout. Then you will have to work ceaselessly to try to recover access. Actually that crumpled paper wallet that's been through the wash and was forgotten in a random drawer in your old house will be much safer to use than this company's support.
And this screed doesn't even touch on their incredibly shady exchange practices. They have how many VCs backing them and couldn't manage to make an exchange that scaled to meet demand at a crucial juncture? Either their funders haven't done due diligence or the technical faults were all part of their plan.
Coinbase puts a lot of work and effort into their security models. Storing coins yourself means that you now have to:
1) Physically secure your private key
2) Secure the machine that you use to interact with that private key
3) Ensure that that private key was generated in a secure way
4) Ensure that the ways that you interact with that private key don't cause any problems.
etc.
Storing your own keys is a bet that you are better at security than coinbase's team. That's not a bet I necessarily want to make.
You can take your old phone or tablet, apply any available upgrades, factory reset it, use it only for crypto currency stuff.
Our mobile operating sysmtems are pretty secure (in the grand scheme of things)
All these people recommending phones or hardware wallets as being easy, and not mentioning the complexity and opsec of offsite backup....
Since you're probably wondering, the passphrase mnemonic on my Ledger is a group of 24 words that represent a translation of the primary secret key. All accounts on my Ledger are derived from it. I've tested wiping and restoring, and the passphrase now lives in my bank deposit box.
By the nature of cryptocurrency, if you had all the public keys from your hardware wallet you could use it as a bank by dropping the wallet itself in a safe deposit box. You don't need it in your physical possession to receive, only send. I'm considering buying a second for exactly this purpose, though at that point, a paper wallet would be just as functional.
> Our mobile operating sysmtems are pretty secure (in the grand scheme of things)
Not yet. Maybe after Android One / Project Treble runs on the majority of smartphones in the world. Which won't happen since Google made Android Go for low-end devices.
That's three problems. Security of the device(s), the lack of redundancy, and the physical security of the device.
A hardware wallet (such as Trezor or Ledger Nano S) together with a smartphone (or PC) yields you 2FA. "(Or PC)" could mean an offline Linux distribution on a USB key which is used as backup. The hardware key suggests a paper backup which should be safely stored at a notary or safety deposit box. Same for the USB key with the backup Linux distribution. Though it can also just contain some config files (stored encrypted).
Such a hardware key costs <= 100 USD/EUR (plus the costs of the notary or safety deposit box) so for any amount of cryptocurrency _above_ the cost of that it is worth it.
These costs are peanuts for the average BTC user, but for people in poorer countries its sadly quite an investment. Worth it though.