Post
Topic
Board Wallet software
Re: Cold Wallet Myth
by
LoyceV
on 04/09/2023, 10:34:12 UTC
2- If we are sure that there is no malware or something in the computer
Allow me to quote Under Siege 2: "Assumption is the mother of all fuckups".

Quote
what difference does it make to connect that cold storage computer sometimes to the internet to make transactions?
The difference is being sure it's not compromised before it's too late Wink

I just want to know that in an IDEAL WORLD, the Electrum wallet on the computer with an internet connection is safe if there is no Malwares, no hacker's attempt etc
In an ideal world we'd have unicorns everywhere. There's not really a point discussing something that doesn't exist.

Quote
We use Cold Storage only to avoid any possible risk that comes through the Internet, Right?
Wrong. It also protects you against your own stupid mistakes. Example:
In June, 2016, I accidentally copied the private key for 1foreverDArUNEX2gVD26vautcx3b8zTZ in my Google search bar. That's been bugging me ever since. It still holds a small balance (~), which isn't what I worry about (and I still use it for tips).
I've downloaded my data from Google, and it confirms Google still knows the private key. It's not something I worry about that much, but it's a loose end to tie up.

Quote
if we are sure that there are no vulnerabilities in the system, then we can connect to the internet.
The whole reason of using cold storage is because you can't know all vulnerabilities. For laughs:
What normally happens within twenty minutes? That's how long your average unprotected PC running Windows XP, fresh out of the box, will last once it's connected to the Internet.
~
20 minutes is not long enough to update your Windows PC before it is too late.
That's a while ago, but there's no reason to think it won't happen now.

I consider TAILS safe enough for me.
Are you talking about cold or hot storage? It's easy to have 2 USB sticks, paint one blue and the other red. The cold one doesn't have internet and holds your private keys, the red one has internet and a watch-only wallet.

Quote
Don't rely on a single USB flash device, be it with TAILS or some other encrypted container or other valuable data on it, as such devices can fail. Cheap flash storage is sometimes of questionable quality. No backups, no mercy!
Keep your seed words on paper and you don't have to worry about the USB stick.

There are millions of things to account for your computer's security.  One of them is the net.  Never connecting to the net, and to no network in general can mitigate every possible network attack.
But for how long?
Update: I googled it, and the first thing I found was lifetime eSim for €2.50, to be soldered inside a device. This is very scary, it will create a whole new level of attacks. Imagine replacing someone's hardware wallet with a fake device with esim that instantly broadcasts the PIN. Air gapped devices will need a faraday cage to be sure.