That last one is the real area the things shines. Muun is a 2of2 multisig wallet. You hold BOTH keys, and control them both. But only ONE of them is ever on your phone. Muun provides the service of cosigning your spends. But they only have one key. This means if someone gets your phone? They can't get your bitcoin. You can make 3 different kinds of backups.
I don't know anything about Muun, but would it be possible to set up the wallet as 2 of 3 instead of 2 of 2 multisig? The last key can also be your own personal backup and 2 of 3 takes up the same space as 2 of 2 when spending and using only 2 keys.
*edit* enjoying my new hat with laser eyes.
I think that is a good strategy. I thought of it too (which is also why I think it's genius!
) It seems to me the Muun folks are going for the most absolutely streamlined design they possibly can. And adding a third key would add complexity to a backup. We type folks might appreciate that complexity but their strategy is probably simpler for someone that knows nothing about bitcoin. You just need a password you can remember, a key written down somewhere, and a cloud server to keep the encrypted full b/u. And then the mechanics of the recovery are very well thought out. I tried the email type. It was great. And the tradeoffs they chose are very smart. It's as secure as it can possibly be without being in unfamiliar territory.
The fact they use cloud storage to store a encrypted full backup is also awesome. "Cloud storage" and "bitcoin backup" are concepts that really should be avoided by purists, but for this use, again the tradeoffs are pretty spot on.
All open source, and a tool that can be used to do the restoration if everything else is gone (including the Muun servers, phone etc.).
All the while handling BOTH base layer HD addresses as well as a channel open to Muun on your node. If the channel still exists it is part of the backup, and even in the most "rip cord" situation the channel is closed and the funds returned to a 1 of 1 address you hold the key for.
Having run nodes since the very beginning I am quite familiar with all the potholes along the way in LN security. It has been one of my biggest most nagging doubts about the viability. It's just too convoluted and difficult for even TECHNICAL users.
Muun really give me a little bullish ah-ha (which is why I am yammering here) because they are DOING what I have been waiting to see. Working out the details in a way that just about ANYONE with a modicum internet comfort can safely use the LN without worrying about... well... just about anything.
Last night I sent $50 from Muun to my node. I do not yet have a channel open to Muun (but plan to open one). I was charged exactly NOTHING for this 150k sat transaction. And it felt just like Bitcoin... except it was instant, and free, and immediately spendable.
itshappening.gif