Proposal to address Bitcoin malware



Summary:

The use of multiple signatures for greater security relies on the independence of multiple secrets. However, in scenarios where secrets cannot be shown to retain independence, such as a compromised operating system, the benefit of multiple signatures reduces to making the exploit more difficult to write. This leads to no benefit for the user and a false sense of security. Bitcoin Authenticator is a desktop and mobile app pair that pairs with a phone over Wi-Fi or cloud push, and potentially Bluetooth. It runs on Win/Mac/Linux on desktop and Android on mobile, similar to Lighthouse. It could also be adapted to use BitGo as a third-party key holder with SMS authenticator relatively easily, according to Brian Erdelyi's email. Erdelyi likes the concept of Bitcoin Authenticator but finds it confusing when described as 2FA. He suggests that it may be more accurate to describe it as out of band transaction verification/signing or dual transaction signing. Regardless, he is excited to see others thinking about this type of technology.


Updated on: 2023-06-09T16:10:50.476765+00:00