From a8bf02fa30d7bc02d0a0a4c3dc0bce25a55dd318 Mon Sep 17 00:00:00 2001 From: mmikeww <1900684+mmikeww@users.noreply.github.com> Date: Sat, 16 Jan 2021 23:04:51 -0500 Subject: [PATCH 1/7] add instructions for verifying addresses on offline machine --- _pages/verify-receive-address/advanced.md | 32 ++++++++++++++++++++--- 1 file changed, 28 insertions(+), 4 deletions(-) diff --git a/_pages/verify-receive-address/advanced.md b/_pages/verify-receive-address/advanced.md index 506eb9a..c14d0b7 100644 --- a/_pages/verify-receive-address/advanced.md +++ b/_pages/verify-receive-address/advanced.md @@ -38,11 +38,35 @@ We can improve this by using an offline/dedicated machine, where we install only While this will help protect you against malware on your computer, you are still at risk from an [Evil maid attack](https://en.wikipedia.org/wiki/Evil_maid_attack) with physical access to your computer (or paper printout). Such an "evil maid" could tamper with this software/printout to instead show bitcoin addresses that they control, and trick you into receiving a deposit on their address. -#### Option A: Dedicated Machine -TODO: add instructions for inputting extended public keys & paths (no private keys/seeds) running Electrum, Sparrow, Caravan, or some CLI script. +#### Option A: Offline/Dedicated Machine +You will set up the multisig in the software wallet of your choice by importing the extended public keys for all N seeds from your quorum. -It is recommended to use an eternally quarantined machine, meaning that it is never again connected to the internet and not used for any other purpose. -That way, the attack surface is reduced and you are not at risk of malware on an ongoing basis. +It is recommended to use an eternally quarantined machine, meaning that it is never again connected to the internet and not used for any other purpose. That way, the attack surface is reduced and you are not at risk of malware on an ongoing basis. + +Alternatively, you can use Tails, which you might already have used when [setting up your Paper Wallet](https://btcguide.github.io/setup-wallets/paper-advanced). + +1. [Verify](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) that all the Zpubs/xpubs match on both the Cobo and the Coldcard +2. Reboot and run Tails + +##### Electrum + +3. Open Electrum, create a new Multi-signature wallet +4. Move the sliders to use "From 3 cosigners", "Require 2 signatures" +5. Add cosigner 1, by Entering cosigner "key". Do not enter any "seed" +6. Type in the first Zpub that is [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard. Click Next +7. Repeat for cosigners 2 and 3 +8. You can skip setting a password, since this wallet will be deleted when Tails shuts down anyway +9. The wallet is now created. Go to the Addresses tab to verify the addresses. If you cannot see the Addresses tab, use the menu item for View -> Show Addresses + + +##### Caravan + +3. Turn on Wi-Fi inside Tails, and visit: https://unchained-capital.github.io/caravan/ +4. Turn off Wi-Fi +5. Click "WALLET" +6. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type +6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpubs [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard +7. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify #### Option B: Print the Addresses to Paper One benefit of this is that you could get by without a dedicated machine, and the other is that paper is easier for most people to secure vs a computer. From 5ae8705b2706c7d51ee9557be525e586fdc7a50f Mon Sep 17 00:00:00 2001 From: mmikeww <1900684+mmikeww@users.noreply.github.com> Date: Sat, 16 Jan 2021 23:12:43 -0500 Subject: [PATCH 2/7] fix spellcheck --- _pages/verify-receive-address/advanced.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/_pages/verify-receive-address/advanced.md b/_pages/verify-receive-address/advanced.md index c14d0b7..c0cba39 100644 --- a/_pages/verify-receive-address/advanced.md +++ b/_pages/verify-receive-address/advanced.md @@ -45,7 +45,7 @@ It is recommended to use an eternally quarantined machine, meaning that it is ne Alternatively, you can use Tails, which you might already have used when [setting up your Paper Wallet](https://btcguide.github.io/setup-wallets/paper-advanced). -1. [Verify](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) that all the Zpubs/xpubs match on both the Cobo and the Coldcard +1. [Verify](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) that all the Zpub/xpub keys match on both the Cobo and the Coldcard 2. Reboot and run Tails ##### Electrum @@ -61,8 +61,8 @@ Alternatively, you can use Tails, which you might already have used when [settin ##### Caravan -3. Turn on Wi-Fi inside Tails, and visit: https://unchained-capital.github.io/caravan/ -4. Turn off Wi-Fi +3. Turn on WiFi inside Tails, and visit: https://unchained-capital.github.io/caravan/ +4. Turn off WiFi 5. Click "WALLET" 6. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type 6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpubs [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard From 7d4ac8531496871facd022dcda91bc804d2448c6 Mon Sep 17 00:00:00 2001 From: mmikeww <1900684+mmikeww@users.noreply.github.com> Date: Sat, 16 Jan 2021 23:14:16 -0500 Subject: [PATCH 3/7] fix spellcheck again --- _pages/verify-receive-address/advanced.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_pages/verify-receive-address/advanced.md b/_pages/verify-receive-address/advanced.md index c0cba39..83268b2 100644 --- a/_pages/verify-receive-address/advanced.md +++ b/_pages/verify-receive-address/advanced.md @@ -65,7 +65,7 @@ Alternatively, you can use Tails, which you might already have used when [settin 4. Turn off WiFi 5. Click "WALLET" 6. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type -6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpubs [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard +6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpub keys [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard 7. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify #### Option B: Print the Addresses to Paper From 6742d13da824614ac8843ed1ff5e5b48f84169ee Mon Sep 17 00:00:00 2001 From: mmikeww <1900684+mmikeww@users.noreply.github.com> Date: Mon, 18 Jan 2021 01:11:07 -0500 Subject: [PATCH 4/7] update to use specter export for electrum --- _pages/verify-receive-address/advanced.md | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/_pages/verify-receive-address/advanced.md b/_pages/verify-receive-address/advanced.md index 83268b2..5429cfd 100644 --- a/_pages/verify-receive-address/advanced.md +++ b/_pages/verify-receive-address/advanced.md @@ -46,27 +46,25 @@ It is recommended to use an eternally quarantined machine, meaning that it is ne Alternatively, you can use Tails, which you might already have used when [setting up your Paper Wallet](https://btcguide.github.io/setup-wallets/paper-advanced). 1. [Verify](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) that all the Zpub/xpub keys match on both the Cobo and the Coldcard -2. Reboot and run Tails ##### Electrum -3. Open Electrum, create a new Multi-signature wallet -4. Move the sliders to use "From 3 cosigners", "Require 2 signatures" -5. Add cosigner 1, by Entering cosigner "key". Do not enter any "seed" -6. Type in the first Zpub that is [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard. Click Next -7. Repeat for cosigners 2 and 3 -8. You can skip setting a password, since this wallet will be deleted when Tails shuts down anyway -9. The wallet is now created. Go to the Addresses tab to verify the addresses. If you cannot see the Addresses tab, use the menu item for View -> Show Addresses +2. In Specter, click on your `Wallet Name -> Settings -> Export -> Export to Wallet software -> Download Electrum (watch-only) File` +3. Save this file to USB stick or SD card. Something that you can access from Tails. +4. Reboot and run Tails +5. Open Electrum, on the first window, click "Choose" and find the wallet file that you exported above in step 2 +6. The wallet should open. Go to the Addresses tab to verify the addresses match the addresses shown on the hardware wallets. If you cannot see the Addresses tab, use the menu item for View -> Show Addresses ##### Caravan +2. Reboot and run Tails 3. Turn on WiFi inside Tails, and visit: https://unchained-capital.github.io/caravan/ 4. Turn off WiFi 5. Click "WALLET" 6. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type 6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpub keys [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard -7. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify +7. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify the addresses match the addresses shown on the hardware wallets #### Option B: Print the Addresses to Paper One benefit of this is that you could get by without a dedicated machine, and the other is that paper is easier for most people to secure vs a computer. From 061f81445c7db07c1b535f5a394bd8cc297c5dcf Mon Sep 17 00:00:00 2001 From: mmikeww <1900684+mmikeww@users.noreply.github.com> Date: Mon, 18 Jan 2021 01:12:19 -0500 Subject: [PATCH 5/7] add note how to show more addresses on Cobo --- _pages/verify-receive-address/cobo.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/_pages/verify-receive-address/cobo.md b/_pages/verify-receive-address/cobo.md index 0c04884..d8803c3 100644 --- a/_pages/verify-receive-address/cobo.md +++ b/_pages/verify-receive-address/cobo.md @@ -8,5 +8,7 @@ The large screen and true airgap improve both security and useability. On Cobo Vault, click `Multisig Wallet` > `Receiving` tab (default selected) and click on the address: ![](/assets/img/verify-receive-address-cobo.jpeg){:width="35%" class="border_image"} +To see more addresses, return to the `Receiving` tab, and press the big `+` button to add more addresses + {% include next_steps.md next_url="coldcard" next_name="Verify Receive Address on Coldcard" %} From 98a9797a659d3ecf0f22f19c52cd8af7f2def423 Mon Sep 17 00:00:00 2001 From: Michael Flaxman Date: Mon, 18 Jan 2021 15:36:04 -0600 Subject: [PATCH 6/7] Fix list items to work better with #67 --- _pages/send-bitcoin/advanced.md | 12 ++++++------ _pages/setup-wallets/index.md | 4 ++-- _pages/verify-receive-address/advanced.md | 24 +++++++++++------------ 3 files changed, 20 insertions(+), 20 deletions(-) diff --git a/_pages/send-bitcoin/advanced.md b/_pages/send-bitcoin/advanced.md index a3888dd..ed2201a 100644 --- a/_pages/send-bitcoin/advanced.md +++ b/_pages/send-bitcoin/advanced.md @@ -13,12 +13,12 @@ Fortunately, your wallet software will abstract this away for you. SD Card is a better airgap, and preferable over signing through USB. 1. On the previous page, at Step 9, choose "Sign with SD Card file" instead of choosing "Sign with USB" -2. Click Save transaction, and save to your SD card -3. Eject the SD card from computer, and load into Coldcard -4. Click "Ready to sign" on Coldcard and confirm transaction details -5. Coldcard will save the signed transaction back to the SD card, but with the `-part` suffix at the end of the filename -6. Back in Specter, click "Load transaction from file", and choose the file on the SD card with the `part` suffix -7. Broadcast +1. Click Save transaction, and save to your SD card +1. Eject the SD card from computer, and load into Coldcard +1. Click "Ready to sign" on Coldcard and confirm transaction details +1. Coldcard will save the signed transaction back to the SD card, but with the `-part` suffix at the end of the filename +1. Back in Specter, click "Load transaction from file", and choose the file on the SD card with the `part` suffix +1. Broadcast #### Inspect Signed Transactions Before Broadcasting diff --git a/_pages/setup-wallets/index.md b/_pages/setup-wallets/index.md index d7ed09f..9e7e5dd 100644 --- a/_pages/setup-wallets/index.md +++ b/_pages/setup-wallets/index.md @@ -9,8 +9,8 @@ We're going to configure a `2-of-3` multisignature scheme, meaning you will have The three wallets / keys will be: 1. A "paper wallet" key intended only for backup/recovery purposes - To simplify setup (and reduce upfront costs associated with hardware purchases), this key will be generated on your computer. By design this key is only for backup/recovery, and therefore will hopefully never be needed. -2. A key generated by your Cobo Vault hardware wallet -3. A key generated by your Coldcard hardware wallet +1. A key generated by your Cobo Vault hardware wallet +1. A key generated by your Coldcard hardware wallet While there are a lot of steps here, you only ever need to do them once. After setup is complete, you will be able to generate (nearly) infinite addresses and sign (nearly) infinite transactions. diff --git a/_pages/verify-receive-address/advanced.md b/_pages/verify-receive-address/advanced.md index 5429cfd..ddbc39c 100644 --- a/_pages/verify-receive-address/advanced.md +++ b/_pages/verify-receive-address/advanced.md @@ -49,22 +49,22 @@ Alternatively, you can use Tails, which you might already have used when [settin ##### Electrum -2. In Specter, click on your `Wallet Name -> Settings -> Export -> Export to Wallet software -> Download Electrum (watch-only) File` -3. Save this file to USB stick or SD card. Something that you can access from Tails. -4. Reboot and run Tails -5. Open Electrum, on the first window, click "Choose" and find the wallet file that you exported above in step 2 -6. The wallet should open. Go to the Addresses tab to verify the addresses match the addresses shown on the hardware wallets. If you cannot see the Addresses tab, use the menu item for View -> Show Addresses +1. In Specter, click on your `Wallet Name -> Settings -> Export -> Export to Wallet software -> Download Electrum (watch-only) File` +1. Save this file to USB stick or SD card. Something that you can access from Tails. +1. Reboot and run Tails +1. Open Electrum, on the first window, click "Choose" and find the wallet file that you exported above in step 2 +1. The wallet should open. Go to the Addresses tab to verify the addresses match the addresses shown on the hardware wallets. If you cannot see the Addresses tab, use the menu item for View -> Show Addresses ##### Caravan -2. Reboot and run Tails -3. Turn on WiFi inside Tails, and visit: https://unchained-capital.github.io/caravan/ -4. Turn off WiFi -5. Click "WALLET" -6. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type -6. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpub keys [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard -7. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify the addresses match the addresses shown on the hardware wallets +1. Reboot and run Tails +1. Turn on WiFi inside Tails, and visit: +1. Turn off WiFi +1. Click "WALLET" +1. On the right side of the page, set 2 of 3 quorum, and set P2WSH address type +1. On the left side of the page, select the dropdown to "Enter as text", and type in all 3 of your Zpub keys [shown](https://btcguide.github.io/setup-wallets/coordinate-multisig-advanced) on either your Cobo or Coldcard +1. Allow Caravan some time to generate the wallet, and then use the Addresses tab to verify the addresses match the addresses shown on the hardware wallets #### Option B: Print the Addresses to Paper One benefit of this is that you could get by without a dedicated machine, and the other is that paper is easier for most people to secure vs a computer. From a73940156b374979a08e45232e3d58a8741afac4 Mon Sep 17 00:00:00 2001 From: Bruno Sette Date: Fri, 5 Feb 2021 18:34:47 -0300 Subject: [PATCH 7/7] Add Umbrel as a bitcoin core node (#79) --- _pages/equipment.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/_pages/equipment.md b/_pages/equipment.md index 3fe90b8..5b768ce 100644 --- a/_pages/equipment.md +++ b/_pages/equipment.md @@ -37,8 +37,10 @@ You do not need to use a laptop, any desktop computer can work. We find laptops ## Bitcoin Core Node For regular users, we recommend using [RaspiBlitz](https://shop.fulmo.org/raspiblitz/), -[MyNode](https://mynodebtc.com/), or -[Nodl](https://www.nodl.it/) +[MyNode](https://mynodebtc.com/), +[Nodl](https://www.nodl.it/), or +[Umbrel](https://www.umbrel.io/) + (more [here](/setup-computer/)). For advanced users, you can [run your own Bitcoin Core node](setup-computer/bitcoin-node) for more details.