Proposal: Bitcoin Secure Multisig Setup



Summary:

In a recent discussion on the bitcoin-dev mailing list, the topic of multisig setup context was raised. The concern is that in the event of a fire where you only recover your steel engraved mnemonic(s), but no longer have the wallet descriptors, you could lose access to your coins. However, it was pointed out that devices need to persist the descriptor, and if they can't comply with this standard, they can't be used securely for multisig. Additionally, there's no reason why the master seed and descriptor both can't be backed up outside of each device. The BIP48 was also discussed as being redundant with descriptors. A proposed updated hierarchy for multisignature wallets can be found on Github. Another concern raised was an encryption convention for the descriptor data since backup location owners cannot spend, but they can view wallet balance/history. It was suggested that Shamir Secret Sharing could be used for this purpose. Finally, the issue of plain text vs binary was addressed with a preference for plain text. Overall, it was agreed that multisig setup context is important and should be taken into consideration when developing multisig setups.


Updated on: 2023-06-14T17:34:35.793501+00:00