CryptoConsortium / CCSS

The CryptoCurrency Security Standard
https://cryptoconsortium.github.io/CCSS/
139 stars 79 forks source link

Downloadable software wallets vs. Online Service #3

Closed ghost closed 9 years ago

ghost commented 9 years ago

I am a bit unclear about how these standards would be applied to the different types of wallets. On the one hand you have downloadable software programs such as Armory, Multibit, Core Client etc. Then you have online services such as blockchain.info that create keys via the web site. Then you have services that maintain the accounts themselves with no access to the private keys. It is difficult to apply a single standard to these different types of models.

mperklin commented 9 years ago

Great question, Milly.

CCSS does not apply to wallets alone, and this is by design. Even if you use the "best" wallet out there and enable all of the "most secure" settings, if you export your private key and back it up in a word document on your fileserver for safe-keeping, your coins can get stolen just the same.

Securing cryptocurrencies does depend on strong wallet software, but it also depends on secure hardware, strong policies, procedures, and trained staff to execute them.

This is why CCSS applies to "Information Systems" that secure cryptocurrencies, and not wallets alone.

I hope that helps clarify,

--Michael

mperklin commented 9 years ago

Closing issue after clarifying the scope of CCSS is for Information Systems and not just wallet software.