@sid_nirvana_fi: encrypt keys with an encrypted key to eliminate loss/theft risk
@sid_nirvana_fi: encrypt keys with an encrypted key to eliminate loss/theft risk by mishaderidder.eth13110 🥝 • 5mo • | |
AI summary of the linked articleThe author argues that private keys should never be stored in plaintext, and that encrypting them with an encrypted master key removes the loss and theft risks of paper or hardware-wallet backups. The post shows an age-encrypted file as an example of what a "paper key" should look like. It criticizes Ledger hardware wallets, which ship with a plaintext key on paper, and describes a six-step process: create a master encryption key, encrypt it with a strong password, shred the plaintext master key, use it to encrypt the wallet private keys, shred those plaintext keys, and decrypt the master key when signing. The post says copies of the encrypted keys can be stored freely, since a strong password means a leak does not matter. | |
but where to store your password 😅 to encrypt the master key lol … but interesting, fyi this is done with age file encryption https://github.com/FiloSottile/age Age encryption seems to have become a new standard. The master key should be -- or protected by -- a hardware/software key combination, so eg a password + fido stick. (At least two sticks, they seem to "age" too.) But so why is this better than just keeping a secret seed phrase? Also wouldn't the master key password at least have to be 6 words from a Diceware word list? Have you tried this? I haven’t tried (yet), but the benefit could be you only have one password (which obviously has to be very secure and preferably only in your mind) which protects all of the seeds you might have. And more importantly you can subsequently store all your seeds on plain paper in encrypted form just anywhere, also the master key doesn’t matter. Even post them on X :). But smart way to go is to combine the master key with a yubikey, that is possible. So you can use the yubikey for normal use and the master key as a backup. If you forget or lose the master key or password, you have the yubikey and the other way around. For a while I used Nitrokeys as the primary and the password as a backup, but providers changed to passkeys or phones instead 😖 and made that problematic. For really significant stuff, I sometimes used LUKS with key and password/pin. | |
Characters remaining: 10,000 comment guidelines | |
More from firefly.social on Kiwi News
| |
