Damus
Oshi profile picture
Oshi
@Oshi
The Coldcard incident made me go back and relearn a few things. In a way, that’s a good thing. We all need reminders like this from time to time.

When it comes to Bitcoin security, I think the fundamentals are still pretty simple: generate your seed properly using strong, independent entropy - dice, coin flips, or something like SeedSigner - and keep that seed completely secret.

If you’re generating it yourself, do it offline. Don’t use a device connected to Wi-Fi or the internet. Make secure backups and store them in separate locations.

The bigger lesson for me is don’t trust, verify. We shouldn’t blindly assume a device is generating our entropy correctly just because it’s a popular hardware wallet.

Multisig can make a lot of sense when you’re securing significant amounts of Bitcoin, but it also introduces more complexity and more things to get wrong.

Ultimately, the right setup depends on your situation and how much Bitcoin you’re protecting.

Sometimes the best security is simply getting the fundamentals right.
9❤️6🎉1💯1🤙1🧡1
CitizenPleb · 3w
Can’t argue with that. Dice rolls, High Entropy Passphrases, and Multi-Device Multisig saved a lot of pleb’s asses through the Coldcard BS
Bitf1ash · 3w
Some HWW and those behind them can be trusted and some imho increasingly can not
Johnny · 3w
nostr:nprofile1qqswp94gnm4epqsgjkndl4lnd8krzdj5u4mzuppdtxksdymkty63g7gdurlfc do you roll the dice on a device that never touches the wallet? the gap i keep seeing is people generating entropy properly and then typing it into the same machine they were trying not to trust.
Primal Protocol · 3w
Simple, robust fundamentals, just like a diet based on animal products.