Case – Insanely Secure Hardware Bitcoin Wallet
techcrunch.com
techcrunch.com
Errrr.... 'embedded' does not mean secure. While you may not have the full software stack of, say, Android or iOS, that doesn't make it secure by default. There's a network interface, some sort of processor, a variety of input devices etc.
I would hope that before making claims like "malware/virus proof" they would get both the hardware and software audited, as credit-card terminals generally have to be.
Other fun thought: if Case goes under, your BTC are now unusable. Good thing hardware startups never fail...
Though there is the possibility that an adversary could get access to the third key and the key that they store for being tied to the biometrics?
But I think that that is probably sometimes a lower risk than the risk of "oops, I lost/forgot my bitcoin key" if one is using single signature? (depending on the person, and their adversaries)
Companies that do succeed at this however should all receive an award for it, or at least be listed somewhere, because it's a really hard problem to solve at times.
I think in certain aspects Apple got this sort of stuff right with the iPhone, but I'm not sure about that, at least I hope iOS is as restrictive as it is for a reason.
Here's a snippet from the FAQ on their website: "During first time setup for the device, you can choose where you want your recovery key stored. The default option is to store it in a secure vault operated by Third Key Solutions. If you wish to store your own third key, you will be prompted during the setup flow to scan the public key of your recovery private key. Please note that you will be responsible for signing a transaction with this private key if your device is lost or stolen, and we recommend this only as an advanced option for expert users." [1]
I'll stick with my Tresor thank you. Cheaper, smaller.
Does this mean biometric data is stored on Case's servers?
The banks or any device you give your money to in the first place, you have to trust.
Otherwise keeping all money with yourself is the only alternative. A sock below the mattress or buried in the garden.
Don't forget to draw a coded (!) treasure map ;-)
So I may conclude bitcoin is not the ultimate answer to distrust and/or in-dependency ?
But for pure bitcoin transactions, no, you can run all the stuff yourself, maintain your own wallet and transact with anyone you like, all without needing anything other than functional bitcoin client software. You need to trust the bitcoin network as a whole, but not any individual authorities.
I'm really not a fan of BTC, personally, but I have looked into it quite a lot...