Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are three widely-used approaches to managing your own keys:

1. Store the keys on your own device, and also write them down on paper as a backup.

2. Store the keys on a dedicated piece of hardware, and also write them down on paper.

3. Encrypt the keys with a username/password and back that up to the cloud.

Option 2 protects against all kinds of malware, including keyloggers. The device has its own screen and buttons, so you can see the backup keys and verify the destination of the funds without trusting you PC.

For the paper backups in options 1 and 2, there are fireproof options like cryptosteel.

Option 3 gives a really nice UX, since it's feels like a standard username/password login. This is what Lastpass does for passwords, but applied to Bitcoin. Keyloggers are still a threat, and if your password is weak, someone might brute-force it in a database breach situation. Depending on your use-case, this may be worth the tradeoff.

The company I work for, Airbitz, implements option 3. In our experience, far more people lose funds accidentally than due to hackers (at least with self-managed keys). Therefore, a familiar UX is crucial to helping users retain control of their funds. Plus, most people aren't willing to invest in specialized hardware, at least at first. If crypto-currencies are ever going to go mainstream, there needs to be a software-only on-ramp.



While I tend to fully agree with everything you are saying wouldn't it be a nice side effect if Bitcoin / crytocurrency dominance forced the average computer user to get serious about password creation and management?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: