Blind signatures for Bitcoin to secure BTC storage
blog.oleganza.com
blog.oleganza.com
I personally love how Electrum wallet does it:
You may generate and regenerate wallet using only key word phrase. Keep it safe in memory or in bank deposit box.
No backups needed. You may always regenerate wallet by keyphrase.
Doesn't Electrum do this by backing up your wallet to "the cloud"? Even if it is 100% properly encrypted, I can't say that I feel good about this. Feels like one bug away from compromising many people's wallets.
https://electrum.org/seed.html
The screenshot uses ecdsa.org, which seems to be just an Electrum server of some kind.
https://en.bitcoin.it/wiki/Thin_Client_Security
It knows which transactions are relevant because of the keys that can be deterministically generated from your seed, but the seed itself isn't sent to a server.
With Electrum you have to have a fully trusted machine to sign transactions. Using M-of-N multisig transaction is safe even if NSA secretly owns your machine.
No, it seems to discuss something else. It starts out talking about blind signatures, then veers off with claims like this:
"The novelty of the scheme is that unlike the original Chaum blind signature scheme, this one does not allow anyone to prove that the signing party signed a particular message"
I am not actually sure what you are trying to say there. Does it mean that I can only narrow down the possible signers to some group? Does it mean that the signature key is ephemeral, yet somehow meaningful?
To put it another way, what differentiates your proposal from this:
https://eprint.iacr.org/2011/402.pdf
""Multiparty computation" with "threshold system" here are provided by Bitcoin automatically, "
What? Where? Citation needed.
What can be done I just thought up is adding another transport layer to bitcoin. And breaking up and distributing the wallet's contents "sum" among strangers into something like a checksum. Then on transactions bringing the chunks of checksum partially back together.
How it's broken down can vary. you have to remember though, if you are buying something for $10 all that needs to be verified is that you have $10 or more for the next step.
If you really want secure storage you print out your private key's and store them in one or more vaults. If your even more paranoid you can encrypt the information such that you need more than one vault to access the data, but have some redundancy so if one storage location floods you don't lose any bit-coins. Which is where these N of M encryption schemes become useful.
My idea is more along the lines of instead of pulling out a wad of money you're only pulling out $50 at a time.
Me personally, I don't mind the wallet amount being public because for things lie fundraising it keeps people honest.
In my paper I propose using sequential generation of parameters so you can break down your funds into multiple transactions, but it's only for convenience, your privacy vis-a-vis your friends is still absolute.
Is there a way to get Btc out if that site goes down?
Keybase is a single point of failure. Or your machine that will do KDF. M-of-N multisig transactions are way safer because to sign a specific transaction you never need to have all secret material at once on a single machine. If my PC is compromised, I can still independently verify specific transaction I want to sign and send it out to my friends to sign. All their private keys are stored on independent machines which normally aren't compromised altogether by the same attacker.
On specific problem with brainwallets - low entropy. One specific problem with web apps: no code signing. Even if your SSL pubkey is pinned (which is not supported by any browser yet), the code you receive from the server is never remembered and pinned (like with installed apps). If their server is silently compromised tomorrow, someone may humbly hijack keys of 1% of the users and go undetected for quite some time.
> which you obviously haven't read before asking
This blew my mind; so unkind!Here's the motivation, right on the first page:
"This can be viewed as an ultimate solution for secure storage of bitcoins as no individual computer system can be fully trusted (e.g. even RNG may leak information about private keys through ECDSA signatures [5]). By spreading the trust between several independently operating computers the risk is significantly reduced. The attacker not only has to compromise several computers instead of just one, but beforehand they must find out which computers are involved (which is made much harder when blind signatures are being exchanged). Therefore the scheme enables safer Bitcoin storage on conventional personal computers and smartphones without need for specialized hardware or compromising privacy."
To my excuse, I only allowed myself to be a bit arrogant while providing a respectful answer anyway. This both answers the question and signals that something can be improved in the discussion.