Shamir's Secret Sharing Scheme (2005)
point-at-infinity.org
point-at-infinity.org
Aside from my regular backups on Blu-ray (unencrypted), I've got two hard disks that hold the same data (and will be updated infrequently, once a year at most).
This is my disaster fallback: house burning down, me awakening from a coma without remembering any passwords or whatever.
Those hard disks are stored in the houses of two friends. And they are encrypted (BTW, that's not only for my peace of mind, but also for theirs: I wouldn't be comfortable holding personal information of my friends unencrypted).
The password to the encryption is split into n parts, such that very close family and friends get more parts and more remote friends get fewer parts. But noone can recover it without cooperation of at least one other.
Printed onto a sheet of paper, together with a clear description (including actual command line invocations) how those shares were generated and how they can be combined). Distributed to a lot of friends. That description is important and must be abundantly clear. Not necessarily to your grandma, but if she shows it to someone who knows at least a bit about computers, he must be able to make sense of it.
But seizing the key-holding devices from your inner circle can be used by law enforcement (or an unfavourable regime) to recover your data without your consent, and you have no way of stopping them.
I don't know a solution to the problem - in the case you lose knowledge of your pass-phrases, external memory is a requirement and such an attack would probably always be possible.
If someone knows a way to have both amnesia- and dictator-proof encrypted storage, I'd love to know about it!
And apart from that they can just seize my unencrypted home backup.
Unencrypted, because I want to be able to restore the rest if a bit flips in some file. And my PAR3 tests were really unconvincing.
Is this a realistic concern? Is a bluray disc at risk of flipping its bits?
Sorry, I'm thinking too much about flipping bits and soft errors at work...
Perhaps by practicing typing the encryption key day after day, you could record it in muscle memory and it would be amnesia proof.
Or perhaps you could invent a unique hand-dance (think hand-jive) and practice it daily, and you could write a program that could decode the sequence into a key.
https://www.schneier.com/blog/archives/2010/07/dnssec_root_k...
[1] http://uncovering-cicada.wikia.com/wiki/What_Happened_Part_1... (breif overview)
For example, let's say a dissident posts a dangerous leak to a bunch of sites in encrypted form. They then distribute the key to 60 of their friends with a threshold of, say, 25 (slightly more than 1/3) and say "combine your keys if anything happens to me."
2. You get to pick how many parts are needed to reconstruct, e.g. three of seven parts required.
Slightly more concretely: I can split a secret value s into two parts by randomly choosing a line that has X intercept s, then giving the value of the line at 1 and at 2. Neither of these alone gets me any closer to finding s, but if I know them both, then I can trivially get s.
Also, splitting the parts up directly means you can't do "any t of n is good enough" where t != n and t != 1.
That doesn't have to be true. Rather than splitting an AES key K into substrings, a better approach is to choose n parts such that:
K_1 ^ K_2 ^ ... ^ K_n = K
None of the component K_i will reveal any information about K without knowledge of its peer components.ABCDEFGH
K1 K2 K3 K4 K1 K2 K3 K4
K1: AE K2: BF
and so on.. ?
In many applications, though, you want to allow a subset of the parts to reconstruct the key. You might want, say, 8 people to have key shares, but want any 3 of them to be able to reconstruct the key. Shamir's makes this kind of setup easy.
What exists already, though, is something similar. Instead of fitting a polynomial through the points (=secret shares), where the intercept would be the full secret, there is a scheme where the full private key is just the simple multiplication of the secret shares.
From there, the co-signers use Pallier encryption to collaboratively compose the signature without revealing their secret parts to each other. It only works with two co-signers at the moment. Here is a demo:
The security solution consists in forcing the attacker to attack lots of machines and successfully control them in order to steal the money.
Here's my suggestion on how to use multisig with blinding so you can lock your bitcoins with N friends and have your financial privacy at the same time: http://oleganza.com/blind-ecdsa-draft-v2.pdf
Prototype for iOS (using my CoreBitcoin objc library): http://github.com/oleganza/blindsignaturedemo