🚀 BR076 - Sparrow, AnchorWatch, Exploding Pagers, Bitcoin Core Spam Attack, Ark goes mainnet, NBitcoin Secp256k1 Vulnerability + MORE ft. @craigraw , @Rob Hamilton , @Carman & @DETERMINISTIC OPTIMISM 🌞 Listen to the episode: ➡️ Fountain: ➡️ Spotify: ➡️ Amazon: ➡️ Apple: ➡️ YouTube: Shownotes: ➡️ Website: ➡️ Substack: Rob explains the paradigm shift in what AnchorWatch is doing by leveraging miniscript. 👇

Replies (11)

Why do your guests always say "for whoever is still listening" - bruh we like the podcast stop being insecure about being technical that's why we listen 🧑‍💻🤌 Listened to 8 hours of this to/from cottage, best podcast for devs by a mile
**[Bitcoin Safe](https://www.bitcoin-safe.org)** has software seeds (generation and import) only on Testnet. On Mainnet sending transactions requires hardware signers in [Bitcoin Safe](https://www.bitcoin-safe.org). *But why?* **[Bitcoin Safe](https://www.bitcoin-safe.org)** is designed as a long terms savings wallet (single and multisig), eliminating as many *foot-guns* as possible. Software seeds are a *foot-gun*, because: - Software seeds are **unsafe** for any substantial amount, because a general purpose computer is not designed to hold secrets of significant value. - Giving new users the option to create a software seed, might lead to the following **unsafe** behavior: Create software seed, and later port it to a hardware wallet, which gives a false sense of security. - Software seeds makes phishing easier, since users are used to having seeds on a computer. - Software seeds are however useful for developers and therefore **Bitcoin Safe** does offer it for Testnet/Signet/Regtest At every wallet generation **Bitcoin Safe** helps the user to backup the seed words onto paper together with the **descriptor** during the [step-by-step wizard](https://bitcoin-safe.org/page/setup-multisignature-wallet/) with the warning never to type it into a computer or make a picture. image @npub1qdca...zclt Episode 76 discussed different hardware signers and their trade-offs , and it is out of question, that *any* hardware signer is better, than a software seed. Tagging: @The Bitcoin Hole #bitcoin #wallet #bitcoinsafe
Bitcoin.Review's avatar Bitcoin.Review
🚀 BR076 - Sparrow, AnchorWatch, Exploding Pagers, Bitcoin Core Spam Attack, Ark goes mainnet, NBitcoin Secp256k1 Vulnerability + MORE ft. @craigraw , @Rob Hamilton , @Carman & @DETERMINISTIC OPTIMISM 🌞 Listen to the episode: ➡️ Fountain: ➡️ Spotify: ➡️ Amazon: ➡️ Apple: ➡️ YouTube: Shownotes: ➡️ Website: ➡️ Substack: Rob explains the paradigm shift in what AnchorWatch is doing by leveraging miniscript. 👇
View quoted note →
Thanks for the nice discussion about hardware signer trade-offs. I think it is important to highlight that any hardware signer is better than a software seed. That's the reason I disallow software seeds in bitcoin-safe.org
Andreas Griffin's avatar Andreas Griffin
**[Bitcoin Safe](https://www.bitcoin-safe.org)** has software seeds (generation and import) only on Testnet. On Mainnet sending transactions requires hardware signers in [Bitcoin Safe](https://www.bitcoin-safe.org). *But why?* **[Bitcoin Safe](https://www.bitcoin-safe.org)** is designed as a long terms savings wallet (single and multisig), eliminating as many *foot-guns* as possible. Software seeds are a *foot-gun*, because: - Software seeds are **unsafe** for any substantial amount, because a general purpose computer is not designed to hold secrets of significant value. - Giving new users the option to create a software seed, might lead to the following **unsafe** behavior: Create software seed, and later port it to a hardware wallet, which gives a false sense of security. - Software seeds makes phishing easier, since users are used to having seeds on a computer. - Software seeds are however useful for developers and therefore **Bitcoin Safe** does offer it for Testnet/Signet/Regtest At every wallet generation **Bitcoin Safe** helps the user to backup the seed words onto paper together with the **descriptor** during the [step-by-step wizard](https://bitcoin-safe.org/page/setup-multisignature-wallet/) with the warning never to type it into a computer or make a picture. image @npub1qdca...zclt Episode 76 View quoted note → discussed different hardware signers and their trade-offs , and it is out of question, that *any* hardware signer is better, than a software seed. Tagging: @The Bitcoin Hole #bitcoin #wallet #bitcoinsafe
View quoted note →
Glad you enjoyed it :) I don’t agree with this absolute statement though - there are many factors in security. For example, it is entirely possible for a hardware wallet to have poorer entropy (for seed generation) than a software wallet, and it is in general harder to evaluate hardware wallets on this criterion.
I’m not aware of a published issue. But entropy quality is to some extent a scale, and there have been reports of funds lost from early hardware wallets that are difficult to explain by other means. I’d love to see more rigorous review of hardware wallet entropy.