正在加载视频...
视频加载失败
Multisig vs passphrases explained simply! Passphrases introduce a new single point of failure, rather than eliminating single points of failure like multisig.
10,214 次观看 • 25 天前 •via X (Twitter)
36 条评论

Not true. A passphrase is not a single point of failure. You can back it up as many times as you like. Back up the seed and passphrase 3 times and you have 6 pieces of information to keep safe, which is still less backups than you need to back up a 2/3 multisig twice.

Number of things needed for successful recovery of multisig: 3 (2x seed phrases + descriptor) Number of things needed for successful recovery of single sig w/ passphrase: 2 (1x seed phrase + passphrase) I am still pro multisig, but it is objectively easier to lose access.

More Bitcoin will be lost to Multisig complexity than to single-sig + a strong passphrase.

Absolutely not. Just ask any company who actually makes wallets. Passphrases actively result in lost coins on a regular basis. Trezor's Head of Security talked about this on the podcast I did with him a few weeks ago

Very hard to lose your passphrase if you’re spreading it geographically. Can also use something like bitwarden as well

multisig still feels safer than a passphrase tbh

It is much safer

A passphrase is the 2FA for a wallet. A multisig setup is just overcomplicating things and making them worse.

No - a passphrase introduces a single point of failure. A multisig introduces resilience. There is a huge difference and you don't need to overcomplicate multisig.

@mynymbox For multisig you need to backup 4 things: 3 keys and a descriptor file. For single sig w passphrase you need 4 things: 2 seed backups, 2 passphrase backups. No single point of failure. Easier to understand for most people.

If you watch the video you'll hear my argument that a passphrase is actually harder to understand for most people. They think it's a password and you can just reset it if needed. Lots of lost coins because of this. Multisig is so easy to understand. You need 2 keys to unlock the door to your vault. What is so complicated?

I don’t usually try to explain as passphrase vs multisig because they’re two completely different and useful tools that can also be combined in some setups.

Yes but lots of people in the community do explain it as passphrase vs multisig ("Multisig is too complex, just use a passphrase") - so I was addressing that

I see that too. Unfortunately Shamir Secret Sharing is also compared with multisig.

Can SHRINCS hash-based efficiently multi-sig? Nick! pls!

If Casa completely disappears one day—its company, servers, and app—and the app no longer works at all, how can I recover and move my BTC from a standard 2-of-3 vault using a Mobile Key and one hardware wallet? Please explain the exact independent recovery process and what I must back up beforehand.

A passphrase does not split the secret. It adds a second way to lose the same complete key. That is extra homework on one object — not a new architecture.

99 Dice Rolls + Strong Passphrase = BYOEntropy Test/ restore your back ups before you seperate and geo-disperse. Share air-gapped, watch only to cordinator + your node for recieving to cold storage. Done. So simple. Never trust someone else’s RNG again. Fool me once, f*ck you! Fool me twice, f*ck me!

with multisig u still need two "keys" to access ur bitcoin. If you lose those two keys u loss ur btc. Same with seed and passphrase it's two keys that you need and if you lose them, you don't have access to your bitcoin. It’s very similar. Don’t lose ur keys. It’s that simple

A passphrase wont protect you long vs a faulty seed

It depends on how long the passphrase is, but the longer the passphrase the more of a risk it becomes itself!

But the wallet descriptor is a "single point of failure" then

multi sig with multi vendor! 2 coldcard hww and casa, you'd still be rugged, unless you had good entropy.

We had people in this situation, and none of them lost money. Zero funds were lost from Coldcards in multisig anywhere that we know of, even when Coldcard was a threshold of keys. Hackers went after the low hanging fruit (single sig) first and that gave multisig time to move

👍 moving the coins was top priority!

Multi-sig is certainly more secure, but a strong passphrase is sufficient for the average user.

No, a passphrase is a footgun for the average user

Okay, that's true. But multi-sig is even more complicated, isn't it?

if ufeel that a passphrase represents a problem, Just write it down with your seed

A passphrase you forget is just a lost wallet. Seen it happen. If you use one, write down where it lives and test a full restore on a spare device. Boring, but it is the part that saves you.

But the descriptor is also a single point of failure. It is also one that is hard to store, use for recovery, and not able to store in a brain wallet. But what do I know? I'm just a low IQ boomer pleb. Oh wait... here's Andreas:

Passphrases feel like progress until the recovery drill fails Multisig forces the threshold into the process itself, no single device, location or person who can walk with the set I run every ceremony that way. The day you need the keys is not the day you want to discover the backup was the real single point of failure

You're conveniently leaving out the benefits of passphrases and the risks of multi-sig especially multi-vendor where one is compromised the entire key is at risk and should be regenerated.

My only issue with multisig is how to backup the descriptors offline, on a medium that doesn't decay.

Why not back up the descriptor online in redundant cloud backup (e2e encrypted if you're worried about privacy)? Or if you use a multisig service they hold it for you

This is why I developed the Guardian Vault. Lets every user upgrade their existing wallet to act like a multisig for assets. 20+ blockchains compatible. Testnet soon, no live deployments until after audits.


