BlockchainCommons / SmartCustody

Overview of SmartCustody Topics, for Responsible Key Management
Other
42 stars 9 forks source link

Review/Feedback of Scenario-Multisig #8

Closed BitcoinQnA closed 2 years ago

BitcoinQnA commented 2 years ago

Hi Guys,

Ken passed on your 'Scenario-Multisig' for review and feedback. I've just read through and think it's an excellent resource that is incredibly detailed and well structured. My feedback follows and is in chronological order with the article.

1 - SSKR is not defined or referenced here. For those that might skip straight to the multisig section, I'd suggest referencing this.

2 - Typo here.

3 - Suggest linking to an industrial grade microSD card in this section.

4 - Here, you could make reference to verifying the entropy supplied using a tool like Ian Coleman (offline).

5 - Make reference to verifying the new Passport firmware here.

6 - Spelling error "Keystone 3" here.

7 - Mention here that the 'Verify Address' feature on Passport can be used to verify each subsequently generated receiving address shown by Sparrow.

8 - It's importance to stress the sensitivity of this letter and the impacts should it fall into the wrong hands.

9 - Passport's PIN should not have changed. If it has, the device is likely compromised and needs to be rotated out of the configuration.

10 - Spelling error "ordian" here.

11 - Finally, I think it would be beneficial to mention the option of keeping a backup of the Sparrow Wallet export file. This is encrypted by default if the wallet is protected with a password (I'm aware your guide recommends against this). The benefit of the export file, aside from making migration to a new Sparrow instance easy, is that it also backs up all transaction labels.

shannona commented 2 years ago

Thanks. Great specifics for the Passport, and great comments on the rest. Everything you suggested should now be incorporated.