ЁЯз╡Thread: 10 Rules for Verification on a #Bitcoin Hardware Wallet ЁЯСЗ

Rule #1: DO NOT TRUST THE COMPUTER SCREEN.

The very reason for using a hardware wallet is that your computer IS compromised, trusting it makes using the hardware wallet an expensive security theatre (or 2FA at best).
Always verify on the HWW device screen!
Rule #2: Verify your "receive" addresses BEFORE accepting funds.

A compromised computer can be tricked into displaying addresses that belong to an attacker. The only way to make sure you own the addresses is to display them on the HWW device and verify they match.
Rule #3: Verifying change address should be done by the device when sending funds, not before like receive addresses!

It is pointless at best, and misleading at worst, to verify them beforehand like receive addresses...
All hardware wallets support verifying the change address belongs to you AT TIME OF SIGNING A TRANSACTION.
Verifying before that is pointless and error-prone.

Now let's talk some multisig...
Rule #4: Verify the xpub of each hardware wallet used in a multisig quorum on the device it belongs to.

This is not 100% mandatory - but if you're no expert - you really should do it.*
*If a hardware wallet doesn't support displaying the xpub, (like Trezor), it could be fine to just verify each address on it - so long as you verify consistency on all other devices as well, but I wouldn't recommend such a device for non-experts.
Rule #5: Verify "receive" addresses on EVERY device of the multisig quorum.

This is especially true for at least one address (see next rule) but recommended for all. If using a device that you haven't verified the xpub of on-screen, you should verify all receive addresses on it!
Rule #6: While it is best to verify each receive addresses on ALL devices in the multisig setup - you might choose to trust a specific one, verifying the xpub/ first address on all - then the rely only on the "trusted" device - ONLY IF YOU ALSO VERIFY XPUBS...
By that, I mean verify on the "trusted" hww used for general verification, that the xpubs are consistent for all cosigners.
This is needed only once with wallets like ColdCard, Cobo Vault, Bitbox02, and Specter DIY - since they allow saving the multisig xpubs on the device.
With Trezor T - you have to verify the xpubs of cosigners every time - which is why it's not recommended for that purpose - with Trezor One it's simply not possible...

So while you might use a Trezor in a multisig, I would not recommend it to non-experts.
Rule #7: Do NOT use Ledger in a multisig setup! (unless you are an expert or have a very good reason...)

Ledger currently does not allow verifying multisig addresses on the device - nor displaying the XPUB on its screen.
This means you have no way to verify it was not swapped by an attacker in your multisig setup - EVEN IF YOU DO A SUCCESSFUL TEST TRANSACTION!

It is still possible for a (very) sophisticated attacker to make you think it worked, while it was him signing for you...
Rule #8: For convenience, you may print out/ write down a large batch of your receiving addresses - verify all at the same time, and rely on that paper list for your day to day verification.
This is very useful for multisig! - where devices might be distributed in various places.
Rule #9: Multisig change verification should be the same as with Rule #3 - on the device at the time of signing.

Popular devices (besides Ledger as said), can verify that the address you send from and the change address used belong to the same multisig wallet (from same xpubs).
If they fail to verify the change address - they will show it as a standard, independent, recipient - in that case YOU SHOULD NOT MAKE THE TRANSACTION.
This is valid for both single sig and multisig! (although even more relevant for the latter).
Rule #10: Hardware wallets cannot verify your balances - and that's great!

Verifying balances requires getting information from the Bitcoin network - i.e. you need to be online - which would make hww more vulnerable...
This is where a full node comes in!
It is strongly recommended that you run your own Bitcoin full node - and use it as your main source for verifying your balances and transaction history!
For redundancy, you could double-check against block explorers or another node (use a different device for either!).
One last thing: These rules apply to any device you use as a segregated signing device - be it a "traditional" hardware wallet, an airgapped laptop, a mobile phone etc.

If you want to separate your keys without having a security theatre, you should verify on your signing device!
Please note: Some things here might not be fully accurate for the expert user (especially around multisig address verification), but for the less advanced users' sake, I have tried to be on the safe side when things get tricky...
That said, if you see inaccuracies or mistakes (or just have questions), please comment!!

Also check out some more info on multisig setups over at:
https://t.co/dwsl52QeD8 (@mflaxman guide)

More from Crypto

A primer on how to use @coingecko for your crypto data/research/trading needs.

Share it with a friend who needs it!

1/ Getting started with crypto and want to check prices/projects? https://t.co/LFnk4vukxj has info on just about every crypto you'll need :)


2/ Search over 6000+ cryptocurrencies available on the market. You can see what's trending in the space as well.

Researching by categories? Filter (left side) -> Select categories -> DeFi, DOT ecosystem, Exchange-based tokens, NFTs - anything!


3/ Lets say you're looking at #Bitcoin
https://t.co/g205lj03pG

At a glance you get:
- Price
- Mkt Capitalization (valuation)
- Circulating/Total supply
- 24h trading volume
- Links to websites, social media, block explorers
- Calculator

Next - check valuation?


4/ Market cap is used to rank coins, and we'll show you how its calculated - Hover over Circulating Supply (?) for breakdown.

Note: used @chainlink as example here - https://t.co/Jc46fe79Ag

While MC is important also consider product fit, narrative, team, community etc.


5/ If you're trading on AMMs like @Uniswap or @SushiSwap, you can copy the contract address directly to your clipboard.

Using @metamask_io? Add the token directly so it shows as one of the "Assets" that you own in the wallet.

See: https://t.co/94XihMf5oz
ЁЯЪиAltcoin Trading IndicatorЁЯЪи

How to use it. A THREAD.

Please Share.

To use it to buy Altcoins and make a high probability entry, the following conditions needs to be fulfilled.

For a long.
1. A green candle Closes above the cross.
2. Heikin Ashi candle turns green.
3. Price should be above 0.236 Fib from the swing high.


How to add the Indicator.

1. Click on the link and Add it to favorites and apply.
https://t.co/Kn90qgDjMi

2. Or Search it in the tab and then apply it.


The indicator itself the most comprehensive Moving Average Indicator which provides 9 MAs and 13 Different times of MAs.

The base of the indicator was by @insiliconot.

To further enhance it, I have added a cross indicator on the cross which works the best historically on Alts.


Condition 1- The cross.

Entry is made when a Cross occurs on the EMA 13/21.
The indicator automatically indicators the Cross with P for a positive cross or N for a negative cross.

This is the first condition for an Entry.
You are running out of time to get ahead in cryptocurrency.

You know what's coming:

ЁЯФ║я╕П Regulation
ЁЯФ║я╕П More shutdowns
ЁЯФ║я╕П Banks deciding who gets to do business

It's time you got your own crypto wallet.

Don't know how? I'll show you.

/////THREAD\\\\\

METAMASK

What's metamask? It's a wallet. That you -- I mean YOU -- own.

You see, when you buy crypto through an exchange like CoinBase, you own it but only kind of.

If they get

ЁЯФ║ Hacked
ЁЯФ║ Shutdown
ЁЯФ║ Servers crash

-- your money is STUCK.

We are gonna avoid that ЁЯСЗ


First thing,

Go to

https://t.co/JXAp9o5RzJ

You can download it on your computer. It's a browser extension.

Alternatively, go to the app store on your Android or iPhone. It's there too.

As part of the setup process, you will choose a password.

More importantly though...

SEED PHRASE

As you follow the setup process, you will be given a 12-word seed phrase.

WRITE. THIS. DOWN.

Take it down and guard it like the map to Davey Jones' Locker.

THESE ARE THE ONLY WAY TO RECOVER YOUR ACCOUNT.

DO NOT LOSE.

We good? Great.

Let's continue.


Once you're all setup, your MetaMask wallet is going to look something like the picture below.

See where it says Crypto Address? That's where your actual address will be.

It'll be a random arrangement of letters, numbers, etc.

Click on it to copy to your clipboard

NEXT STEP

You May Also Like

"I lied about my basic beliefs in order to keep a prestigious job. Now that it will be zero-cost to me, I have a few things to say."


We know that elite institutions like the one Flier was in (partial) charge of rely on irrelevant status markers like private school education, whiteness, legacy, and ability to charm an old white guy at an interview.

Harvard's discriminatory policies are becoming increasingly well known, across the political spectrum (see, e.g., the recent lawsuit on discrimination against East Asian applications.)

It's refreshing to hear a senior administrator admits to personally opposing policies that attempt to remedy these basic flaws. These are flaws that harm his institution's ability to do cutting-edge research and to serve the public.

Harvard is being eclipsed by institutions that have different ideas about how to run a 21st Century institution. Stanford, for one; the UC system; the "public Ivys".
#роЖродро┐родрпНродро┐ропро╣рпНро░рпБродропроорпН ро╕рпНродрпЛродрпНродро┐ро░роорпН
роЗродрпБ роЪрпВро░ро┐роп роХрпБро▓родрпНродро┐ро▓рпН роЙродро┐родрпНрод роЗро░ро╛роорокро┐ро░ро╛ройрпБроХрпНроХрпБ родрооро┐ро┤рпН роорпБройро┐ро╡ро░рпН роЕроХродрпНродро┐ропро░рпН роЙрокродрпЗроЪро┐родрпНродродро╛роХ ро╡ро╛ро▓рпНроорпАроХро┐ роЗро░ро╛рооро╛ропрогродрпНродро┐ро▓рпН ро╡ро░рпБроХро┐ро▒родрпБ. роЖродро┐родрпНроп ро╣рпНро░рпБродропродрпНродрпИродрпН родро┐ройроорпБроорпН роУродро┐ройро╛ро▓рпН рокрпЖро░рпБроорпН рокропройрпН рокрпЖро▒ро▓ро╛роорпН роОрой роороХро╛ройрпНроХро│рпБроорпН роЮро╛ройро┐роХро│рпБроорпН роХро╛ро▓роорпН роХро╛ро▓рооро╛роХроХрпН роХрпВро▒ро┐ ро╡ро░рпБроХро┐ройрпНро▒ройро░рпН. ро░ро╛роо-ро░ро╛ро╡рог ропрпБродрпНродродрпНродрпИ


родрпЗро╡ро░рпНроХро│рпБроЯройрпН роЪрпЗро░рпНроирпНродрпБ рокро╛ро░рпНроХрпНроХ ро╡роирпНродро┐ро░рпБроирпНрод роЕроХродрпНродро┐ропро░рпН, роЕрокрпНрокрпЛродрпБ рокрпЛро░ро┐ройро╛ро▓рпН роХро│рпИродрпНродрпБ, роХро╡ро▓рпИропрпБроЯройрпН роХро╛рогрокрпНрокроЯрпНроЯ ро░ро╛роорокро┐ро░ро╛ройрпИ роЕрогрпБроХро┐, рооройро┐родро░рпНроХро│ро┐ро▓рпЗропрпЗ роЪро┐ро▒роирпНродро╡ройро╛рой ро░ро╛рооро╛ рокрпЛро░ро┐ро▓рпН роОроирпНрод роороирпНродро┐ро░родрпНродрпИрокрпН рокро╛ро░ро╛ропрогроорпН роЪрпЖропрпНродро╛ро▓рпН роОро▓рпНро▓ро╛ рокроХрпИро╡ро░рпНроХро│рпИропрпБроорпН ро╡рпЖро▓рпНро▓ роорпБроЯро┐ропрпБроорпЛ роЕроирпНрод ро░роХроЪро┐роп роороирпНродро┐ро░родрпНродрпИ, ро╡рпЗродродрпНродро┐ро▓рпН роЪрпКро▓рпНро▓рокрпНрокроЯрпНроЯрпБро│рпНро│родрпИ роЙройроХрпНроХрпБ

роиро╛ройрпН роЙрокродрпЗроЪро┐роХрпНроХро┐ро▒рпЗройрпН, роХрпЗро│рпН роОройрпНро▒рпБ роХрпВро▒ро┐ роЙрокродрпЗроЪро┐родрпНродро╛ро░рпН. роорпБродро▓рпН роЗро░рпБ роЪрпБро▓рпЛроХроЩрпНроХро│рпН роЪрпВро┤рпНроиро┐ро▓рпИропрпИ ро╡ро┐ро╡ро░ро┐роХрпНроХро┐ройрпНро▒рой. роорпВройрпНро▒ро╛ро╡родрпБ роЪрпБро▓рпЛроХроорпН роЕроХродрпНродро┐ропро░рпН роЗро░ро╛роорокро┐ро░ро╛ройрпИ ро╡ро┐ро│ро┐родрпНродрпБроХрпН роХрпВро▒рпБро╡родро╛роХ роЕроорпИроирпНродро┐ро░рпБроХрпНроХро┐ро▒родрпБ. роиро╛ройрпНроХро╛ро╡родрпБ роЪрпБро▓рпЛроХроорпН роорпБродро▓рпН роорпБрокрпНрокродро╛роорпН роЪрпБро▓рпЛроХроорпН ро╡ро░рпИ роЖродро┐родрпНроп ро╣рпНро░рпБродропроорпН роОройрпНройрпБроорпН роирпВро▓рпН. роорпБрокрпНрокродрпНродро┐ роТройрпНро▒ро╛роорпН роЪрпБро▓рпЛроХроорпН

роЗроирпНродродрпН родрпБродро┐ропро╛ро▓рпН роороХро┐ро┤рпНроирпНрод роЪрпВро░ро┐ропройрпН роЗро░ро╛рооройрпИ ро╡ро╛ро┤рпНродрпНродрпБро╡родрпИроХрпН роХрпВро▒рпБро╡родро╛роХ роЕроорпИроирпНродро┐ро░рпБроХрпНроХро┐ро▒родрпБ.
роРроирпНродро╛ро╡родрпБ ро╕рпНро▓рпЛроХроорпН:
ро╕ро░рпНро╡ роороЩрпНроХро│рпН рооро╛роЩрпНроХро▓рпНропроорпН ро╕ро░рпНро╡ рокро╛рок рокрпНро░роиро╛роЪройроорпН
роЪро┐роирпНродро╛ роЪрпЛроХ рокрпНро░роЪрооройроорпН роЖропрпБро░рпН ро╡ро░рпНродрпНродройроорпН роЙродрпНродроороорпН
рокрпКро░рпБро│рпН: роЗроирпНрод роЕродро┐родрпНроп ро╣рпНро░рпБродропроорпН роОройрпНро▒ родрпБродро┐ роороЩрпНроХро│роЩрпНроХро│ро┐ро▓рпН роЪро┐ро▒роирпНродродрпБ, рокро╛ро╡роЩрпНроХро│рпИропрпБроорпН роХро╡ро▓рпИроХро│рпИропрпБроорпН


роХрпБро┤рокрпНрокроЩрпНроХро│рпИропрпБроорпН роирпАроХрпНроХрпБро╡родрпБ, ро╡ро╛ро┤рпНроиро╛ро│рпИ роирпАроЯрпНроЯро┐рокрпНрокродрпБ, рооро┐роХро╡рпБроорпН роЪро┐ро▒роирпНродродрпБ. роЗродропродрпНродро┐ро▓рпН ро╡роЪро┐роХрпНроХрпБроорпН рокроХро╡ро╛ройрпБроЯрпИроп роЕройрпБроХрпНро░роХродрпНродрпИ роЕро│ро┐рокрпНрокродро╛роХрпБроорпН.
роорпБро┤рпБ ро╕рпНро▓рпЛроХ ро▓ро┐роЩрпНроХрпН рокрпКро░рпБро│рпБроЯройрпН роЗроЩрпНроХрпЗ роЙро│рпНро│родрпБ
https://t.co/Q3qm1TfPmk
роЪрпВро░ро┐ропройрпН роЙро▓роХ роЗропроХрпНроХродрпНродро┐ро▒рпНроХрпБ рооро┐роХ роорпБроХрпНроХро┐ропрооро╛ройро╡ро░рпН. роЪрпВро░ро┐роп роЪроХрпНродро┐ропро╛ро▓рпНродро╛ройрпН роЬрпАро╡ро░ро╛роЪро┐роХро│рпН, рокропро┐ро░рпНроХро│рпН
I hate when I learn something new (to me) & stunning about the Jeff Epstein network (h/t MoodyKnowsNada.)

Where to begin?

So our new Secretary of State Anthony Blinken's stepfather, Samuel Pisar, was "longtime lawyer and confidant of...Robert Maxwell," Ghislaine Maxwell's Dad.


"Pisar was one of the last people to speak to Maxwell, by phone, probably an hour before the chairman of Mirror Group Newspapers fell off his luxury yacht the Lady Ghislaine on 5 November, 1991."
https://t.co/DAEgchNyTP


OK, so that's just a coincidence. Moving on, Anthony Blinken "attended the prestigious Dalton School in New York City"...wait, what? https://t.co/DnE6AvHmJg

Dalton School...Dalton School...rings a

Oh that's right.

The dad of the U.S. Attorney General under both George W. Bush & Donald Trump, William Barr, was headmaster of the Dalton School.

Donald Barr was also quite a


I'm not going to even mention that Blinken's stepdad Sam Pisar's name was in Epstein's "black book."

Lots of names in that book. I mean, for example, Cuomo, Trump, Clinton, Prince Andrew, Bill Cosby, Woody Allen - all in that book, and their reputations are spotless.