-
side-trips[m]
I heard there's a small chance secret service might have invented xmr
-
cockliuser[m]
Better yet, the NSA
-
cockliuser[m]
Nicholas SAberhagen
-
cockliuser[m]
NSA
-
side-trips[m]
What's the goto if that gets revealed as true? Zcash?
-
meow[m]
side-trips[m]: Wownero
-
ofrnxmr[m]
side-trips[m]: Zcash was invented by nsa
-
ofrnxmr[m]
One of the trusted signers is even snowden lol
-
ofrnxmr[m]
Criminal scammer
-
ofrnxmr[m]
Dev fee 20%, guy always side talking monero and boosting his bags
-
ofrnxmr[m]
Zcash an an alternative to what? Another scam, perhaps.
-
ofrnxmr[m]
Tech is only as good as its implementation
-
meow[m]
<ofrnxmr[m]> "One of the trusted signers is..." <- he's such a traitor, can't believe he released our national secrets and fled to russia.
-
meow[m]
he was probably a russian spy even before he released those documents.
-
ofrnxmr[m]
And shilled zcash the whole time
-
ofrnxmr[m]
<side-trips[m]> "I heard there's a small chance..." <- And if it was, who cares? We're here now
-
side-trips[m]
Feel like they could have some backdoors or 0-days
-
dreamcity[m]
<side-trips[m]> "Feel like they could have some..." <- Unless, you have a strong and concrete reason to think otherwise, who cares right? I mean, It will always be impossible to prove a negative and It might be easier to target low hanging fruit. Why target monero itself, when you can target the super insecure computers and smartphones most people are keeping their coins on, lol
-
dreamcity[m]
That being said, we shouldn't let our guards down and still verify, but I wouldn't lose my sleep over it.
-
k4r4b3y[m]1
Monero will end involuntary taxation.
-
Mumuks
From the two companies that do Monero hardware wallets, Trezor and Ledger, what do people here prefer and why?
-
chesterfield[m]
Ledger just added kyc backup for your key
-
DataHoarder
can just not use it
-
Mumuks
<chesterfield[m]> "Ledger just added kyc backup for..." <- Yeah, I'm aware:
beincrypto.com/ledger-recover-cloud-seed-phrase-feature
-
Mumuks
That is one of the reasons I'm leaning Trezor. But they are big Block stream ass lickers, so I would prefer something else. But seems they are the best option for Monero.
-
cockliuser[m]
<DataHoarder> "can just not use it" <- Still, Ledger is closed source that already makes Trezor 2x better
-
cockliuser[m]
There's also the WIP Monero firmware for the Passport wallet
-
DataHoarder
is trezor hw open source? I guess they don't include a secure element
-
DataHoarder
ledger apps themselves are open source, though
-
DataHoarder
secure elements are finicky cause, yeah, not many out there are open source
-
cockliuser[m]
DataHoarder: Apps?
-
cockliuser[m]
I'm talking about the hardware and firmware
-
DataHoarder
but without the secure element you can just extract the keys from an offline token (then just protected by pin, bypassing limits)
-
cockliuser[m]
Both of those are open source for Trezor
-
DataHoarder
-
DataHoarder
yep, trezor to do that lacks a "secure element"
-
DataHoarder
which opens a different kind of attacks, making a "pin/password tries limit" not really hold up
-
cockliuser[m]
The passport wallet has a secure element iirc
-
DataHoarder
is that secure element also open source? I need to refresh my memory in the ones that are
-
cockliuser[m]
Don't think so, but everything else is
-
cockliuser[m]
-
cockliuser[m]
Ledger also had many data leaks in the past
-
DataHoarder
yeah using any of their "cloud" or "site" services is insane
-
DataHoarder
don't do it
-
DataHoarder
thankfully not related to the hw itself
-
DataHoarder
both Trezor / Ledger have also been affected by security issues, Trezor response is nice
-
DataHoarder
but most of Trezor ones keep coming up all the time and some are unworkable due to physical access = memory stolen
-
DataHoarder
I think I have the initial Passport version around
-
dreamcity[m]
cockliuser[m]: What I say will be controversial, but most hardware wallets were never supposed to be invincible, nor for long term storage of crypto. They were just supposed to be a convenient way of holding a small amount of crypto for transactions in a "secure enough" way against casual attackers.
-
DataHoarder
^ I use them mainly for multisig setups
-
cockliuser[m]
Hardware wallets are just small airgapped computers
-
DataHoarder
it's convenient indeed
-
cockliuser[m]
cockliuser[m]: They're much more secure than software wallets IMO because of the airgapped part
-
cockliuser[m]
But closed source ones add that element of "trust" that I don't like
-
sech1
ledger is not airgapped because it technically can send out the seed
-
k4r4b3y[m]1
dreamcity[m]: I can do the latter on a regular computer or phone, too. So if that was the goal, why buy an extra device?
-
dreamcity[m]
cockliuser[m]: More secure than hot wallets (sw wallets on a pc connected to internet)? Sure. Compared to an airgapped pc wallet, It's not always obvious which one is more secure and It depends a lot
-
cockliuser[m]
Yeah but most people aren't going to set up an airgapped computer for signing transactions
-
dreamcity[m]
<k4r4b3y[m]1> "I can do the latter on a regular..." <- I don't disagree, but a hardware wallet is always going to be a bit more secure than a regular smartphone (even the "insecure" and poorly implemented hardware wallets), It's still a little peace of mind even for small transactions. But your point stands indeed.
-
k4r4b3y[m]1
dreamcity[m]: > <@dreamcity:matrix.org>
-
k4r4b3y[m]1
> I don't disagree, but a hardware wallet is always going to be a bit more secure than a regular smartphone (even the "insecure" and poorly implemented hardware wallets), It's still a little peace of mind even for small transactions. But your point stands indeed.
-
k4r4b3y[m]1
the point isn't whether a smartphone or a hardware wallet more secure. The point is, for small amounts (as you posit the scenario) you don't need that high security anyways.
-
ofrnxmr[m]
About as secure as your trust level in the company
-
ofrnxmr[m]
Ledger doesnt even show correct xmr seed
-
ofrnxmr[m]
Break your usb port or screen, then what?
-
ofrnxmr[m]
ledger releases a breaking update OTA, then goes out of business, then what?
-
ofrnxmr[m]
Do you trust that your ledger will work in 15 years? Or plan on buying the lastest every couple years?
-
sech1
seed engraved on a steel plate to the rescue
-
ofrnxmr[m]
so why would i need a hw wallet
-
ofrnxmr[m]
If i have a seed backup, hw wallet doesnt protect ne
-
ofrnxmr[m]
Purpose of hw wallet it to avoid being brute forced, no?
-
dreamcity[m]
sech1: This, but unironically. For long term storage, encrypted paper wallets at multiple physical locations + brain wallet (remembering the key) should be more than overkill to not lose keys
-
ofrnxmr[m]
To be able to spend without ever risking keys
-
dreamcity[m]
ofrnxmr[m]: If you plug in your hardware wallet to an untrusted computer connected to internet, you are taking a small risk (there can be vulnerabilities and It happened in the past in some hw vendors)
-
ofrnxmr[m]
safer if i just use ny phone
-
ofrnxmr[m]
Plugging into random usb ports, or devices ive left unattended = sill to me
-
ofrnxmr[m]
Store my big bucks on a paper wallet
-
ofrnxmr[m]
Probably just as easy (easier) to crack into my bank app as to get into cake wallet
-
ofrnxmr[m]
I dont use a hw wallet for my bank app 🫡
-
k4r4b3y[m]1
<sech1> "seed engraved on a steel plate..." <- > <@sech1:libera.chat> seed engraved on a steel plate to the rescue
-
DataHoarder
14:59:11 <ofrnxmr[m]> Do you trust that your ledger will work in 15 years? Or plan on buying the lastest every couple years?
-
k4r4b3y[m]1
redpill me on this. I understand that the steel plate protects against fire hazards, but I can't bring myself to have my seed words lying around unencrypted, easy for the seeing.
-
DataHoarder
no, as sech1 said, seed words stored
-
DataHoarder
I setup an extra "passphrase" each time to use the ledger/trezor/etc.
-
sech1
you can engrave an encrypted seed on a steel plate, and keep the password in your head
-
sech1
Monero CLI/GUI wallets have support for this
-
k4r4b3y[m]1
sech1: > <@sech1:libera.chat> you can engrave an encrypted seed on a steel plate, and keep the password in your head
-
k4r4b3y[m]1
cool.
-
mlcboss[m]
<sech1> "you can engrave an encrypted..." <- why not qr code on paper
-
sech1
paper burns
-
vdo
it can also decompose
-
vdo
not safe long term
-
mlcboss[m]
cover it in plastic
-
nioc
if you keep a password in your head you can keep a seed in your head
-
nioc
but the head is not a safe place for anything
-
mlcboss[m]
nioc: i save all my password in a memory palace
-
mlcboss[m]
but yeah i hit by a car and i will forget everything
-
dreamcity[m]
nioc: It is safe, but It's still better to have backups, just in case.
-
dreamcity[m]
mlcboss[m]: > <@mlcboss:matrix.org> i save all my password in a memory palace
-
dreamcity[m]
>
-
dreamcity[m]
> but yeah i hit by a car and i will forget everything
-
dreamcity[m]
If you forget everything, you can forget where you put your steel plate too :P . At some point, you will have to cut corners and not be too paranoid
-
nioc
it is safe until it is not
-
nioc
as always people have different risk tolerance
-
nioc
sorry guys but my coins will still be able to be used after imma gone :D
-
mlcboss[m]
<dreamcity[m]> "> <@mlcboss:matrix.org> i save..." <- i store my paper seed in my wallet
-
lza_menace
my favorite band on Project Coral Reef no longer takes XMR at their store :sad_pepe:
-
mlcboss[m]
<lza_menace> "my favorite band on Project..." <- why? government ban?
-
nioc
no, aliens
-
plowsof11
Can we sponsor aliens to start making Monero themed crop circles
-
nioc
best marketing idea ever
-
riceandbeans
Would you give out your monero address or generate a new address within your wallet for each person?
-
k4r4b3y[m]1
riceandbeans: New address per person
-
riceandbeans
How many addresses can I have with a wallet?
-
mlcboss[m]
riceandbeans: infinite
-
riceandbeans
That's my favorite number
-
MajesticBank