Comparing Multisig and Shamir Secret Sharing

15 replies 437 views
Posts: 84 · Reputation: 29
#1Aug 12, 2017, 02:58 PM
A lot of folks just stash their private keys or recovery phrases in one spot. But if you’ve got a decent amount of coins or share your wealth, it’s smart to look at alternatives. Overcomplicating things can backfire and lead to losing everything just from one mistake. Multisig and Shamir Secret Sharing are two popular options I wanna compare.
5 Reply Quote Share
Posts: 172 · Reputation: 24
#2Aug 12, 2017, 08:20 PM
I'm convinced that a lot of multisig issues will be solved once we get Schnorr signatures and Taproot. Those signatures should boost privacy, so no one can see multisig transactions or who’s signing. Plus, signature aggregation will merge them into one, which might lower fees and speed up signing too... right?
4 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#3Aug 12, 2017, 08:42 PM
Just updated the Trezor info regarding Shamir Secret Sharing. SLIP39 allows you to break down a seed phrase into shares, and then further divide those shares. It’s kinda like a double-layer security approach. But seriously, what’s the point of that?
2 Reply Quote Share
Posts: 8 · Reputation: 94
#4Aug 13, 2017, 06:39 AM
Why not just encrypt your seed instead? You'd have an encrypted seed and an encryption key kept separate. No need to worry about complicated implementations or safety risks since encryption algorithms are solid and already in all crypto libraries.
3 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#5Aug 13, 2017, 09:46 AM
Honestly, SSS feels pointless if one person holds all the shares. At some point, they’ll need to gather them all to access the funds. That just opens the door for an attacker to grab everything.
4 Reply Quote Share
Posts: 110 · Reputation: 19
#6Aug 14, 2017, 08:41 AM
That’s not really a disadvantage. For any secret sharing, you need data from when the shares are made. For multisig, that info isn’t secret, you could share it on your blog. But with secret sharing, that data is sensitive and would need encryption before sharing.
1 Reply Quote Share
Posts: 84 · Reputation: 29
#7Aug 14, 2017, 12:52 PM
Both Multisig and Shamir Secret Sharing work better when you’re distributing keys among multiple people and locations. If someone finds an encrypted seed, they could try to extort or brute force it. With Multisig, they’d need access to multiple places and people to get to your funds.
2 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#8Aug 14, 2017, 01:52 PM
True, but even with multiple shares, one person still needs to gather them for reconstruction.
3 Reply Quote Share
Posts: 84 · Reputation: 29
#9Aug 14, 2017, 04:07 PM
Yeah but you see the issue, right? 🤷‍♂️
2 Reply Quote Share
Posts: 84 · Reputation: 29
#10Aug 14, 2017, 05:04 PM
Check the history next to the edit button. The whole article was written by one guy except for the Trezor part.
0 Reply Quote Share
Posts: 2 · Reputation: 204
#11Aug 14, 2017, 07:21 PM
Wow, a lot of Gmaxwells in this discussion, huh?
2 Reply Quote Share
Posts: 110 · Reputation: 19
#12Aug 15, 2017, 12:59 AM
Trezor updated Shamir Secret Sharing to SLIP39, and that’s the new standard for their devices. If you’re lost on the differences and pros/cons of BIP39, SLIP39, and Multisig, check out this video I found. Also, here’s an open-source tool for converting BIP39 to SLIP39.
6 Reply Quote Share
Posts: 95 · Reputation: 8
#13Aug 15, 2017, 06:10 AM
Just be careful when using multisig or splitting your seed phrase. There are risks.
0 Reply Quote Share
Posts: 3523 · Reputation: 35
#14Aug 15, 2017, 06:57 AM
SSSS is pretty cool, honestly. Seems like a more advanced method than multisig. We need to figure out how to split the shards without a central point, though. There are some on-chain methods that might work.
1 Reply Quote Share
Posts: 3523 · Reputation: 35
#15Aug 15, 2017, 08:43 AM
Nah, I think it’s a worse and less secure option. Just saying. For those who missed it, check this link about Shamir's Secret Sharing.
5 Reply Quote Share
Posts: 3523 · Reputation: 35
#16Aug 15, 2017, 11:08 AM
A lot of experts say seed splitting is a bad idea. Newbies should stick to simpler backup methods that are easier for wallet recovery later. Even if you know what you’re doing, splitting seeds can be risky.
3 Reply Quote Share

Related topics