Author

Topic: Casa Keymaster? (Read 224 times)

newbie
Activity: 15
Merit: 1
June 22, 2020, 03:00:58 PM
#4
I've come across this new service called Casa keymaster. I'm aware that some of the subscriptions offered there are probably meant for businesses and not the average user but has anyone used them before and could give us a review and tell us whether it's worth it or not.


I have been using their service and I haven't had any problems.
newbie
Activity: 25
Merit: 66
April 20, 2020, 04:14:45 PM
#3
Hi there, I'm the co-founder and CTO of Casa! Just stumbled across this thread and figured I'd chime in to address concerns.

To start off, we've outlined our threat model and design decisions here in our Wealth Security Protocol: https://docs.keys.casa/wealth-security-protocol/.

Quote
Hardware wallets such as Trezors and Ledgers should be received directly from the manufacturer.

This is a valid concern, and our Gold tier is "bring your own hardware" while our premium tiers include devices. We are authorized resellers for both Trezor and Ledger. Users are welcome to buy directly from them if they wish to further reduce supply chain risk!

Quote
I prefer to not have any backups stored on my iCloud account, even if encrypted.

You can certainly skip backups if you want, though we believe this is the best trade-off between convenience, security, and redundancy for the average user. Advanced users may be capable of securing seed phrase backups, but we believe this is asking too much of casual / mainstream users.

Quote
You should write down your recovery seed when generating a seed on a hardware wallet, and store it in a safe/secure location, preferably in a safety deposit box, or a fire safe in your house.

There are so many risks that go unstated when people say "store your seed phrase in a safe place" that it's laughable. I've performed extensive tests that show many seed backup devices are actually can't withstand common house fires, for example. And if you put a seed phrase in a safety deposit box it's still vulnerable to the bank itself and to state actors that can coerce the bank. We do recommend storing a coldcard in a safety deposit box, however, as the hardware then provides another layer of security against insider / state level attacks.

TL;DR you may not agree with our thesis that the average user isn't capable of securing seed phrases against all of the attacks that our security model protects against, and that's OK.

Quote
They can restrict access to your money

This is a misunderstanding - the Emergency Lockdown feature is not available to 2-of-3 multisig accounts, only to 3-of-5 accounts. When activated on a 3-of-5 account they still have a sufficient threshold of keys to route around our service without the Mobile Key if necessary. We take great care to ensure that Casa can not unilaterally create or block transactions; we strive to eliminate any single points of failure, including our own service. For further clarification you can view our step-by-step recovery guides at https://walletsrecovery.org/recovery-docs/casakeymaster-recovery.html

Also worth noting that for 2-of-3 we support using 2 hardware devices and no mobile key, which I believe alleviates several of the concerns you voiced.

I'm not on this forum often; feel free to direct further questions to me via any of my verified accounts listed on https://keybase.io/lopp or ask our support team at [email protected]!
copper member
Activity: 1652
Merit: 1901
Amazon Prime Member #7
June 03, 2019, 09:11:27 PM
#2
I am not a user, but I looked at their website just now. They look very similar to BitGo, and have a similar business model from an operations perspective.

They appear to be a new company, receiving only $2.3 Million in seed money in March 2018.

Based on my reading and understanding of their website and documentation, you will use their App on your phone that serves as one of three signing keys to a 2-of-3 multi signature wallet. Two of the signing keys will be on a hardware wallet and on your phone. They will have the third signing key, but it is unclear how they sign any transactions for you.

I found some security practices I believe are bad reading their FAQ
-If you sign up for one of their paid plans, they will ship a hardware wallet from their office. Hardware wallets such as Trezors and Ledgers should be received directly from the manufacturer.

-Backups of signing keys intended to be on your phones App will be stored in the cloud:
Quote
    The mobile key is stored within the secure enclave of your phone and encrypted with a another key from Casa.
    Your encrypted mobile key is then uploaded to your iCloud or Android cloud account.
<>
    This means we don’t have access to your private key in any way, but you can recover your key using your iCloud or Android account + the Casa app.

<>
Lost your phone? Don’t sweat it, you can recover your Mobile Key with Casa.

First get another phone. If you had an iPhone it needs to be a new iPhone. If you had an Android, it needs to be an Android phone.

Log into your iCloud or Android account on your phone. Log into Casa. Go to the mobile screen and select “recover mobile key”. The app will direct you from here.
I prefer to not have any backups stored on my iCloud account, even if encrypted.

-They instruct users to not keep backups of a hardware recovery seed:
Quote
DO NOT write down your seed phrase while setting up a Trezor with Casa multisig.
You should write down your recovery seed when generating a seed on a hardware wallet, and store it in a safe/secure location, preferably in a safety deposit box, or a fire safe in your house.

-They can restrict access to your money:
Quote
In the help tab you’ll notice a big red button that says Emergency Lockdown. Beginning at the Gold membership level, you have access to this feature. Press this button if you ever feel like you’re in a dangerous situation where your funds could be at risk. This will freeze any activity across your account indefinitely. Contact us to verify your identity & safety and we’ll unlock you within 48 hours.
I believe this to mean they have the ability to restrict your access to your mobile key available on their App. It does not appear they can access this key, but you will be unable to spend any coin if they restrict access to this key. They would still have access to the third key. This will leave you vulnerable to them restricting access to your mobile key unless you sign a transaction sending some coin to them with your hardware key.

My opinion is you are better off buying a hardware wallet to secure your coin. If you want to use a multi sig setup, you can buy multiple hardware wallets, from multiple manufacturers if you wish.
staff
Activity: 3500
Merit: 6152
June 02, 2019, 10:11:10 AM
#1
I've come across this new service called Casa keymaster. I'm aware that some of the subscriptions offered there are probably meant for businesses and not the average user but has anyone used them before and could give us a review and tell us whether it's worth it or not.
Jump to: