{"id":81948,"date":"2024-07-14T19:49:42","date_gmt":"2024-07-14T19:49:42","guid":{"rendered":"https:\/\/neclink.com\/index.php\/2024\/07\/14\/bitcoin-seed-phrases-the-challenge-of-mainstream-self-custody-adoption\/"},"modified":"2024-07-14T19:49:42","modified_gmt":"2024-07-14T19:49:42","slug":"bitcoin-seed-phrases-the-challenge-of-mainstream-self-custody-adoption","status":"publish","type":"post","link":"https:\/\/neclink.com\/index.php\/2024\/07\/14\/bitcoin-seed-phrases-the-challenge-of-mainstream-self-custody-adoption\/","title":{"rendered":"Bitcoin Seed Phrases: The Challenge of Mainstream Self-Custody Adoption"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/bitcoinmagazine.com\/.image\/c_fit%2Ch_800%2Cw_1200\/MjA3Nzk5ODI0NzA2MjUwMzM5\/default_notes_next_to_a_laptop_with_a_pencil_0.jpg\" \/><\/p>\n<p>An underlying theme of this cycle has been to challenge preconceived notions about how people use Bitcoin around the world. New behaviors are emerging and other cultures are using the asset in a way that is breaking previously established molds. <\/p>\n<p>A major trend emerging out of this chaotic environment is the resurgence of seedless security models, which take a radically different approach to securing Bitcoin private keys. Proponents argue that established security practices are failing to meet the expectations of an increasing number of users. Along with the maturation of custodial alternatives, the emergence of ETF products is creating concerns about the prospect that future users will onboard into more complex self-custodial solutions. <\/p>\n<p>It is not the first time security specialists have pointed the finger at seed phrases when asked about the difficulties of Bitcoin self-custody crossing the chasm. Industry veteran Jameson Lopp has <a href=\"https:\/\/blog.casa.io\/seedless-security-model\/\">long debated<\/a> the challenges of the security model, and remains outspoken about its pitfalls. His company, multi-signature wallet provider Casa, was formed, in part, to address the issues created by traditional backup methods. <\/p>\n<p>In a conversation with Bitcoin Magazine, current <a href=\"https:\/\/casa.io\/\">Casa<\/a> CEO Nick Neuman echoed his colleague\u2019s concerns:<\/p>\n<p>\u201cWe <em>need to think more carefully about how we use them as an industry because the user experience of getting hit with a seed phrase the first time you set up a wallet is very difficult<\/em><em>.\u201d<\/em><\/p>\n<h3>The Perils Of Seed Phrases<\/h3>\n<p>Despite significant progress in the quality of Bitcoin products and applications, the landscape of self-custody remains perilous for those whose comfort with technology stops at their iPhones. Every other day, accounts emerge of various successful phishing attacks targeting victims\u2019 funds by compromising their wallet\u2019s seed phrases. <\/p>\n<p>Earlier this January, popular hardware wallet provider Trezor announced they had reasons to believe sensitive customer information had been leaked due to a breach in the systems of a third-party service provider. In the following months, X users reported a new wave of phishing attempts hitting their inboxes. <\/p>\n<p>Another reminder of the fragile state of the average person\u2019s security practices came in 2022 following a security exploit that affected popular password manager LastPass. <\/p>\n<p>Following a string of curious wallet-draining incidents affecting mobile and hardware wallet users alike, <a href=\"https:\/\/krebsonsecurity.com\/2023\/09\/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach\/\">researchers eventually figured out<\/a> that seed phrases stored on the service\u2019s servers had been compromised. As of a <a href=\"https:\/\/x.com\/tayvano_\/status\/1788039611627000244\">couple of months ago<\/a>, losses have been <a href=\"https:\/\/x.com\/tayvano_\/status\/1788039611627000244\">estimated<\/a> to have reached over $250 million in various cryptocurrencies. <\/p>\n<p>While popular Bitcoin influencers have banged the table for the adoption of more robust security systems involving hardware wallets, a large number of market participants have yet to warm up to this practice. Shehzan Maredia, founder of Bitcoin financial service company <a href=\"https:\/\/bitcoinmagazine.com\/business\/bitcoin-financial-platform-lava-unveils-exchange-and-stable-payments-\">Lava<\/a>, sees a significant divide between security product developers and a large section of the Bitcoin market. <\/p>\n<p>\u201cI\u2019ve realized most people start questioning their ability to self-custody when you involve hardware wallet and seed phrases. Half of them will do a poor job of following instructions and the other half will simply prefer using custodians,\u201d he remarked. <\/p>\n<p>Security experts are adamant that private key material should remain offline at all times, but Maredia suggests secure enclaves present in modern mobile phones are sufficient to thwart the majority of attacks affecting users today. <\/p>\n<p>\u201cLooking at the common causes responsible for the loss of users&#8217; funds, it\u2019s rare to find examples of mobile keys being compromised.\u201d Rather, he argues, it\u2019s more likely users will do a poor job of securing their seed phrase backup or will give it away during a phishing attack. <\/p>\n<h3>Seedless Challenges And Opportunities<\/h3>\n<p>Bitcoin products have seen a lot of improvements since Casa pioneered the seedless wallet approach years ago but few so far have followed in the company\u2019s tracks. While self-custodial applications are more robust than ever, some changes have introduced additional steps to an already significant learning curve. It\u2019s worth questioning whether a nihilistic attitude towards security has pigeonholed the practice into rituals unpalatable to the average person. <\/p>\n<p>Neuman remains optimistic. He suggests there has been an observable shift in the industry towards more realistic approaches, though he thinks Bitcoin products are lagging behind <\/p>\n<p>\u201cThere are still quite a few like wallets that force you to [save your seed phrase] upfront. I think it&#8217;s kind of a risk management thing on their end, but it actually works against the goal of helping users feel comfortable holding their own keys.\u201d<\/p>\n<p>Regardless, the trend suggests the rest of the industry is coming around to the risks of users handling sensitive information. Recent technologies such as passkeys, implemented in Coinbase\u2019s new \u201c<a href=\"https:\/\/help.coinbase.com\/en\/wallet\/getting-started\/smart-wallet#passkeys\">Smart Wallet<\/a>,\u201d offer interesting alternatives for this new generation of products. <a href=\"https:\/\/developers.google.com\/identity\/passkeys\">Passkeys<\/a> are a new standard promoted by internet giants like Apple and Google, which aim to replace traditional passwords with cryptographic keys tied to a user&#8217;s device and identity. <\/p>\n<p>According to our research, t<a href=\"https:\/\/x.com\/johnjohnson\/status\/1811451151096906025\">estimonies<\/a> from <a href=\"https:\/\/x.com\/martypartymusic\/status\/1803829746117284185\">early adopters<\/a> indicate the technology has yet to sort out important standardization issues. Lava\u2019s Maredia agrees there is room for improvement. He recently launched a seedless solution he thinks achieves the best security tradeoffs one can expect of mobile devices.<\/p>\n<p>The Lava Vault draws heavy inspiration from older contributions from ex-Spiral developer Tankred Hase called the <a href=\"https:\/\/docs.photonsdk.org\/\">Photon SDK<\/a>. Photon implements a seedless cloud backup similar to Casa\u2019s early implementation of the mobile key wallet but is fully open-source though it hasn\u2019t been maintained for some time. Maredia is persuaded that the 2-of-2 solution he has adapted from existing designs in the ecosystem can stand against most known attacks.<\/p>\n<p>\u201cWe looked at things like passkeys, but we just don\u2019t think they are made to secure important key material like Bitcoin. They basically swap one piece of sensitive information for another and are usually stored in a password manager. In practice, most password managers do a poor job handling them, they can be deleted very easily even on iCloud.\u201d <\/p>\n<p>Lava secures users&#8217; seed phrases using a high entropy key stored on a different server. Once encrypted, the seed is saved in a special directory on the user\u2019s cloud that can help prevent accidental deletion or malicious access. Users authenticate with a key server, which enforces rate limiting, using a 4-digit PIN of their choice. Lava does not require the creation of any account which preserves users&#8217; privacy from the service and its servers. For daily operations, the wallet uses another key stored on the device\u2019s secure enclave. <\/p>\n<p>\u201cEven if a party accesses encrypted information, there is no single point of failure because they&#8217;d have to know the encryption key. Forgetful users can set up a PIN recovery method which allows them to change their PIN after a 30-day delay.&#8221;<\/p>\n<p>Maredia expects his security protocol to evolve according to users&#8217; needs and different risk profiles. Wallet policies such as 2FA, withdrawal or spending limits, and whitelisted addresses are already on the way. \u201cLava Smart Key is a very flexible solution. Users can upgrade their self-custody setup easily, and we\u2019re open to accommodating users who have specific demands,\u201d he explains. <\/p>\n<p>Although seedless backups have been criticized for exposing individuals to undue third-party risks, open-source implementations like the Photon SDK and Lava\u2019s vault model suggest more vendors and service providers could implement similar standards and mitigate this issue. <\/p>\n<p>Seed phrases remain an important component of the security stack but both entrepreneurs consulted for this article believe it is essential to abstract them from most future users. <\/p>\n<p>\u201cSeed phrases in general, I think, are a very useful tool for making your keys more portable between wallets and giving you that exit option just in case something happens to the wallet software you&#8217;re using,\u201d says Casa CEO Nick Neuman. <\/p>\n<p>To eliminate single points of failure, Casa promotes a combination of multi-sig plans involving hardware devices but insists on sticking to its seedless principles where possible.<\/p>\n<p>\u201cWallet software is made for managing private keys. Humans are not made for managing private keys. So we should leave that job to the wallets.\u201d<\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/bitcoinmagazine.com\/technical\/bitcoin-seed-phrases-the-challenge-of-mainstream-self-custody-adoption\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An underlying theme of this cycle has been to challenge preconceived notions about how people use Bitcoin around the world. New behaviors are emerging and<\/p>\n","protected":false},"author":1,"featured_media":81949,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[151],"tags":[],"class_list":["post-81948","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/81948","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/comments?post=81948"}],"version-history":[{"count":0,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/posts\/81948\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media\/81949"}],"wp:attachment":[{"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/media?parent=81948"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/categories?post=81948"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/neclink.com\/index.php\/wp-json\/wp\/v2\/tags?post=81948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}