Damus
BTC_P2P profile picture
BTC_P2P
@BTC_P2P
After seeing Sparrow wallet passed all audits with flying colors and reading more about how Sparrow handles the BIP39 passphrase and protects private keys I’m curious why a software wallet (via Sparrow) with a strong passphrase isn’t a viable long-term solution?

Or at minimum at least viable as one (convenient) key in a 2/3 multi sig setup.

Can people who understand this stuff on a technical level explain what I am missing in the trade offs? #asknostr
91❤️1🖤1🤙1
Financial Parasites · 4w
Lesson in there…. https://image.nostr.build/e80860b40242e81099b5a1166db33da0668462905b494270f5b36818687635c8.jpg
Kendy · 4w
Pardon me if this is obvious but first attack vector I thought of is if the device running Sparrow software is connected to the internet and vulnerable to spying, key logging, etc.
Jordan Richner · 4w
USB drive with Tails OS. Then never connect it to TOR = cold storage. Tails comes with Electrum wallet by default, but it is possible to install the Linux version of Sparrow on Tails.
Kendy · 4w
Where did you see this result? I’m guess you’re referring to the Red Team? https://xcancel.com/callebtc/status/2085024458012586286#m
Johnny · 4w
nostr:nprofile1qqsweargze9awsah26pakwrsecquhxsafw8vyqldym09p7tz2kauwksmj65ks a passphrase covers the seed at rest. at use you type it into the same machine that already holds the key, so one compromise takes both factors, which is exactly why it works fine as one key in a 2 of 3.