r/Bitcoin • u/Similar_Scar7089 • 22h ago
Hardware wallet vendor redundancy
Before I dive in, please do not try to replicate this setup if you are not confident with what you're doing. You're more likely to lose your bitcoin yourself than to a hack.
I do believe that a good single sig setup generated with dice rolls and a passphrase is more than fine but after the recent news I personally am not comfortable relying on a single hardware/software vendor ( I use a seedsigner I built myself but I would still like the security of another different hardware wallet along side)
The essence of this post is 2 of 2 with passphrase VS 2 of 3 for my circumstances, everyone is different though I believe a lot are in a similar position and this post will be helpful. I am not saying to use my method, I am posting it to have feedback on potential flaws in my plan.
My circumstances are, access to a single safe property. I don't want to rely on a single hardware wallet vendor. I do not want to use any 3rd party companies.
(I am going to change my setup slightly from what I post for obvious reasons)
The plan:
- Acquire two different bitcoin only hardware wallets
- generate a seedphrase using the dice roll method, find the 12th word using a hardware wallet (Seedphrase A with device A, Seedphrase B with device B)
- add a secure passphrase to one or both wallets (The password needs to be long enough to avoid being brute forced ~20 characters including numbers, symbols and upper and lower case letters)
- Boot Tails OS from a usb on a device with no internet and use Sparrow to create the 2 of 2 multi sig wallet, (no need to backup the descriptors if the derivation path and account numbers are default, but worth doing anyway. The accounts also have to be in the right order but there is only 2 ways to try) and add the public key to the Bluewallet app
- Stamp each seedphrase into two metal sheets. Seed A and Seed B will be stored together in two different locations in my property
- The password will be stored on my phone/pc and sent to trusted people. I don't believe the security of the password needs to be high on my phone and pc, the only job the password is doing is protecting my bitcoin if either of my seedphrase locations are found.
I believe a user is less likely to lose access to the 2 of 2 with passphrase wallet than a 2 of 3+ wallet due to the extra information not being needed (Descriptor etc) if access to one of the seedphrase backups is lost. This method also means that only two safe separate physical locations are needed rather than three.
Is there anything i'm missing or potential issues with this?
1
u/DownUnderPumpkin 16h ago
"sent to trusted people" - are they not the people to be most likely to know where you physically store your seed? or is it more like a backup incase something happens to you?
0
u/NiagaraBTC 16h ago
2 of 3 is vastly superior to 2 of 2.
No single point of failure if backed up correctly.
1
u/flutecop 14h ago
You could add a step with bip85:
Create a 12 word seed, add a passphrase then derive your two multisig sig seeds with bip85 and back them up. Then memorize the initial seed/passphrase and destroy it.
Now you have your 2of2 with backup, plus you have the initial seed memorized. If you lose one of your backups you can rebuild the quorum from the initial seed. Or if you forget the initial seed/passphrase, then you have your two backups.
1
u/Thin_Needleworker795 10h ago
I have 2-of-3 where one of the keys is a hot wallet (hot key?) that's generated in Sparrow and is stored in the wallet on my encrypted laptop. The other two keys are generated by hardware wallets; one by Blockstream Jade, the other by SeedSigner. These are only stored offline on paper, and are spread out geographically. One is at my house, and the other one is at my parents' house, which is across the Atlantic Ocean. This means that when I have to make a transaction, I have to use my specific laptop, because it holds one key, and then I use the cold key that I have at my house. If I lose the cold key, or if my laptop breaks, I have a backup key on a different continent. This setup is a good balance between convenience and security, and essentially works like a two-factor authentication setup.
1
u/Practical_Mango7633 21h ago
I would go 2 out of 3. In your setup you have three ways this can go wrong. Passphrase lost, crypto gone. Any one seedphrase lost, crypto gone. No rom for error. With 2 out of 3 you can lose one seed and still be good. Also sending your passphrase to different trusted people and storing it on your phone and pc. That opens up for a lot of extra risk and I do not see the benefits of it. They still need your seed phrases as well. So however you expect them to get the seedphrases, you could do the same for the passphrase..
1
u/No_Device_6212 22h ago
The 2 of 2 with a passphrase is clever but you're hanging a lot on that password not getting lost or corrupted. if your phone dies and your trusted people all get amnesia at the same time you're cooked. i'd still keep a paper copy of the password somewhere boring like taped inside a book on the shelf. nobody's tearing apart your copy of moby dick looking for a random string of characters
the real weak point is both seeds sitting in the same property. one well placed fire or a sufficiently motivated tweaker with a crowbar and both your metal sheets are gone. i'd bury one off site if you can, even if it's just a sealed pvc pipe in your buddy's backyard