Hi zaseb,
thank you for the hot cold wallet description. This part is interesting: "The transactions are signed on this machine, the signed transaction is then moved to an internet connected machine where it is then broadcast to the network."
So I connect the cold wallet never ever to the internet, even if I make a transaction. That's fantastic!
"If your machine is compromised oauth or 2FA won't protect you so it provides no extra security."
Ok, that's a good argument. But if I have no security extras, why should I not use Blockchain.info?
They don't store my key and I can use features like, shared , sms, email ... transactions.
As you say, if I get compromised the hot wallet will be emptied, no matter what API I use.
I will have a look at the Amory Client. Do you have a set-up guide for a hot wallet?
Thanks
DaDeus