Post
Topic
Board Armory
Re: SecurePrint flawed (in the context of fragmented backups)
by
etotheipi
on 21/02/2014, 20:35:07 UTC
Even if an attacker has access to my life I want to make it as difficult for them as possible. You have a lot of nifty solutions for paranoid users and I thought this would be a good complement.

In the meantime I suggest that users who want a little bit of extra security when it comes to the SecurePrint feature, to only write the code down on as many fragments as it is necessary, i.e. N - M + 1 fragments. For example in a 5-of-6 fragmented backup configuration you only need to put down the SecurePrint code on 2 (=6-5+1) fragments and then put these fragments in the locations you deem most secure.

The SecurePrint code is just another piece of data that is needed to unlock your fragmented backups.  You can do what you're saying, or you can just recalibrate your decision of M and N (in M-of-N) to meet your security-vs-redundancy needs.  For instance, use 4-of-7 instead of 3-of-5 and then you haven't destroyed your ability to recover it if particular fragments are not recovered.

Or don't use SecurePrint at all and write all data down by hand from the computer screen.  There's nothing wrong with that.