pull down to refresh
Let's say opti suddenly doesn't have to work anymore. Maybe opti will get himself a good little ESP32, maybe even with wifi like a C5, solders a secure element on top and then opti spends 3-6 months coding himself a signer. I think my signer will be more secure than whatever you buy, whatever laptop or phone you can get your fingers on. I can also choose to do this with a phone - some rock5 based thing perhaps.
So I can answer both ways with 'YES'.
Yes, I can make a dedicated hardware signer more secure than a generic device.
Yes, I can probably also make a generic device more secure than a hardware signer.
The problem is opti needs to work sometimes to not lose even more weight and actually stay alive, and preferably get off the skeletor look in the first place. So, can I practically make a generic device more secure than a dedicated hardware signer that I buy? Probably not right now.
I see that, and I doubt that I will ever have enough Bitcoin to merit learning how to do what you describe above.
However, my question is, given my current capabilities (slightly tech savvy non-dev), how do I weigh the risks of using generic hardware (with what feeble hardening I am able to achieve) against a purpose built device (but which comes with increased privacy risk, honeypot risk, and so on)?
It seems that there is no case where I want to use a single sig because the likelihood that I screw something up is relatively high and I like the idea of avoiding single points of failure. However, an exposed home address linked to a known Bitcoin balance is also a single point of failure, no matter how many signatures is my threshold. So even including a single purchased hardware device opens a while new risk factor.
All of this may not be helpful though as the risks are difficult to enumerate and likely quite different for different individuals.
You'd measure your options in cost * risk * complexity
So for example:
laptop + phone + DIY'd seedsigner -> multisig may be low cost, medium risk but high complexity. So perhaps: usb livecd w/ electrum -> singlesig is better because you still have medium risk but less complexity and lower replacement cost, or maybe even dedicated pixel 8a w/ bluewallet (?) -> singlesig could work too.
Okay, so I can remove the WiFi card and install very basic software.
Do you think a hardware signing device provides any benefit over a generic device that has been carefully hardened?