I know that's not even the proper way to store your coins. But only security experts knew better.
Hint: It was https://electrum.org/. It's amazing.
No wallet software can keep your coins safe if it has to store your keys in the same machine you use for your internet activities. You have to use either an air-gapped machine (also called offline or cold storage) or multi-signature.
Then there's also the issue about trusting what you have downloaded. Even if you run the software in an offline machine, if it's meant to steal your coins it certainly can do it. Do you trust Electrum's developers or whoever reviewed the code? What about the maintainer of the website (or Github)? Did you use SSL? Did you check the signature? Did you get the signature from a different and secure channel?
For now I'm trusting Armory, but I'm planning to move to multi-signature once I have time, and maybe use three different wallets to create the keys.
Losing the keys is a separate issue. You have to think about different scenarios like disk failure, data decay, a fire in your house, your friend dying and their family not letting you recover his part of your n-of-m backup, police raid, etc.
About misplacing the keys, Electrum has deterministic wallets, so you can just print the key and store it somewhere (or remember the ten words it gives you), and your wallet is never lost.
Multisignature, deterministic, open source
But I'm not sure if I like their 2-of-2 scheme. I would rather have a 2-of-3 one. Maybe I should re-read their paper.
Another thing that bothers me is that it's not very safe by default. The only way to be safe is if you use a (reviewed) plugin and you don't let it update automatically. Because if you use Javascript instead, they can take your key whenever they want. Imagine if the FBI seized their servers and injected Javascript malware like they did with Tormail.
2of2 with time locked transactions means you can prevent double spend and thus allow instant confirmation.
the android app doesn't update by default and the chrome app doesn't update if installed from github but otherwise you are right although the web client remains useful for watch only mode (no keys) or for small amount
these two local and open source wallet clients also verify data before signing against the electrum network.
we are also working on our api, plugins for popular open source wallets (including hardware) and a full Java desktop client using bitcoinj.
we also worked hard to make all user transactions non correlatable to users or us (instant confirmation is out of band) and are working on a bunch of interesting things on top of it
Could you explain this more, or link to an explanation?
http://blog.greenaddress.it/2014/04/05/firstpost-updates/
Direct pdf link:
http://ghgreenaddress.files.wordpress.com/2014/04/greenaddre...
Take wallet.
Encrypt wallet.
Put sufficiently complex password on wallet (ie, no dictionary attacks).
Wow, you suddenly have a bank. Feel free to back up that file all you want, hell, if your password is solid you can publish it publically. I wouldn't, since you don't have to, but you still won't password crack it any time soon.
In other words, you're being disingenuous as to how simple it really is to get set up for Bitcoin. There are countless threads on Reddit and the like by confused geeks asking for advice and instructions on wallet generation/encryption/storage/etc.
Hell, throw a brief rundown into whatever their equivalent of "University 101" is if it really does prove to be a problem.
Some people really like tinkering with new tech and are willing to put up with a lot. Others have a low threshold of frustration and might not see it as appealing. This isn't about intelligence, but ease and convenience. And anyone that says with a straight face that setting up BTC for even the average MIT student is a simple endeavor is severely underestimating the complexity and risks involved, especially when the alternative is using the established and relatively risk-free system you've grown comfortable and intimately familiar with for years.
Better $100 of bitcoin than your credit card information.