1/27 A thread on setting up and securing the @FOUNDATIONdvcs Passport to self-custody #Bitcoin

- Unboxing
- Supply Chain Validation
- PIN
-Firmware
- Seed phrase
- Passphrase
- Testing backups
- Connect w/@SparrowWallet
- Multisig w/@COLDCARDwallet
- Additional features
2/27 This thread is the short version of a more detailed article which can be found on @BitcoinMagazine .com

*Keep an eye out for announcements from @FOUNDATIONdvcs, they are anticipating releasing a new version of the Passport around March 2022.

bitcoinmagazine.com/technical/how-…
3/27 UNBOXING

Tamper-evident tape seals the box with no indications of #Bitcoin related contents within. You will find the Passport, startup card, & stickers, The Founders edition includes a copy of the white paper. Everything to start included; batteries & 2x 8GB microSD cards. ImageImageImageImage
4/27 Simply remove the magnetic rear cover, insert the batteries and you're ready to scan the quick-start instructions with your mobile device or webcam for further details. The Passport measures 108 mm in length by 38 mm in width. ImageImageImageImage
5/27 SUPPLY CHAIN VALIDATION

To ensure the Passport has not been tampered with in transit, a public/private key pair is used between the Passport and a publicly displayed QR code. 4 words will be generated on the Passport as a checksum. ImageImageImageImage
6/27 PIN

A numeric PIN is used to secure access to the Passport. 6-12 digits is acceptable. After the initial 4-digits, two anti-phishing words are displayed. Write down the PIN & words, there is no way to recover a lost or forgotten PIN. ImageImageImageImage
7/27 FIRMWARE

Keep the Passport up to date for new features, quality of life improvements, security & bug patches. Check the current version in "Settings>Firmware>Current Version" against the displayed version in the docs: docs.foundationdevices.com/en/firmware-up… ImageImage
8/27 Download the latest firmware, save to microSD. The card will stick out half way. The Passport will only allow firmware to be installed if it has been signed by at least 2 of 4 Foundation developer keys. Full guide demonstrates self-verification. ImageImageImageImage
9/27 SEED PHRASE

The Passport is going to generate 24 English words, that make up the seed phrase. It is a human-readable representation of the signing key for your #bitcoin. The seed is sensitive & should be regarded like cash, gold, or jewelry. Full guide covers written words. Image
10/27 By default, Passport will encrypt & save them to the microSD. The seed phrase can then be decrypted with a password that the Passport will generate. This password is 6 English words. Secure this password, both the file & password are necessary to expose the seed. ImageImageImageImage
11/27 PASSPHRASE

A passphrase adds an extra layer of security to your #Bitcoin wallet. It is additional required info to access your private key. It can be thought of as a "25th word" at the end of the seed phrase. Without the passphrase, the #bitcoin will not be accessible. ImageImageImageImage
12/27 Passphrases can contain any combination of special characters, lower case letters, upper case letters or numbers, easy-to-remember phrases, or even a random high-entropy string of characters. ImageImageImageImage
13/27 Once the passphrase is applied a "P" shield will appear. This is now a totally different wallet than the one you initially logged into. A "fingerprint" is used to identify & ensure the passphrase is entered correctly. ImageImageImageImage
14/27 TESTING BACKUPS

Do not deposit #bitcoin to your new wallet without testing your backups. This means double checking your work, deleting your seed phrase from the Passport, and restoring from your backup whether encrypted file or written words. ImageImageImageImage
15/27 CONNECT w/@SparrowWallet

Sparrow is a desktop #Bitcoin wallet designed to be connected with your own node. It is a user-friendly wallet with many advanced features that enable you to monitor your air gapped Passport balance, generate addresses & create txs. ImageImage
16/27 Passport can export the watch-only XPUB information via QR code or microSD, both are covered in the full guide. ImageImageImageImage
17/27 You can build a transaction in @SparrowWallet then display it as an animated series of QR codes that you can scan with the Passport to sign, then pass it back. Since Sparrow is connected to your own node, you can then broadcast the signed tx to the #Bitcoin network. ImageImageImageImage
18/27 MULTISIG

This is a way to secure your #bitcoin so that signatures from multiple devices are required, like 2-of-3. Using hardware wallets from different manufacturers can mitigate unforeseen vulnerabilities or attack vectors that may be present in one but not another. Image
19/27 In the demo, @SparrowWallet, @COLDCARDwallet, & @FOUNDATIONdvcs Passport are used. This means one of the cosigners is a hot wallet, you may want to use all air gapped devices.

A new wallet was generated in Sparrow for the first keystore: Image
20/27 Then a fresh XPUB from @COLDCARDwallet was imported for the 2nd keystore by navigating to "Settings > Multisig Wallets > Export XPUB". This was transferred via microSD, keeping the ColdCard air gapped. ImageImageImageImage
21/27 The 3rd keystore was imported via QR code from the Passport by navigating to "Pair Wallet > Sparrow > Multisig > QR Code". ImageImageImageImage
22/27 With the 3 keystores imported, deposits can be made to the new multisig wallet via the @SparrowWallet interface. Then to spend, the tx can be built in Sparrow and even signed by Sparrow in this case for 1 of the 2 sigs, but the hardware wallets were used instead. ImageImageImage
23/27 First the built tx was saved to microSD and passed to the @COLDCARDwallet, signed, then passed back to Sparrow all air gapped. ImageImageImageImage
24/27 Second, the tx with 1 sig was displayed in Sparrow via animated QR code and scanned with the Passport for the 2nd sig. ImageImageImageImage
25/27 Once signed, the Passport displayed the QR codes for Sparrow to scan. Then the tx could be broadcast to the #Bitcoin network. You can monitor BitcoinCore, @SparrowWallet, or your preferred block explorer like @mempool for confirmations. ImageImageImageImage
26/27 There is more information that is required for backups with multisig, so be sure you double check your work and test your backups. Then think about how you will distribute this information. Image
27/27 There are additional features in the Passport like:

Screen brightness, auto shutdown, change PIN, BTC units, sign a text file, or import your own public key for firmware builds.

Check out @FOUNDATIONdvcs to learn more.

foundationdevices.com

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with burn the bridge

burn the bridge Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @econoalchemist

Dec 31, 2021
1/10 Getting started with cold storage can be simple; striving for verification, privacy, & security can start to add layers of complexity.

A thread on beginner, intermediate, & advanced user guides I wrote on getting started with @COLDCARDwallet
2/10 These 3 guides start with the most basic steps and add additional precautions as they go along to address the unique needs for a range of users.

The beginner guide is called UltraQuick and can be found on the @COLDCARDwallet website here: coldcard.com/docs/ultra-qui…
3/10 UltraQuick covers checking the tamper-evident bag, setting up a PIN, generating seed words, & connecting to @SparrowWallet.
Read 10 tweets
Dec 8, 2021
1/24 Mining #Bitcoin from home on a private network is an essential part of maintaining a permissionless operation.

A thread on using @pfsense, @WireGuardVPN, & @mullvadnet to build a robust home network & route mining traffic through multiple VPN tunnels without added latency.
2/24 This thread is the short version of a more detailed article which can be found on the @BitcoinMagazine website here: bitcoinmagazine.com/guides/how-to-…
3/24 The full guide can help you:
-Get rid of your ISP's router & build your own firewall
-Configure multiple LANs on your network
-Route your traffic through a VPN
-Configure ad blockers

Special thank you to @_k3tan for helping me with this.
k3tan.com/pfsense
Read 24 tweets
Nov 3, 2021
1/18 Storing clear text secrets without risking it all.

A thread on @COLDCARDwallet's Seed XOR function, what it is, and how to use it. Image
2/18 This thread is the short version of a more detailed article which can be found on the @BitcoinMagazine website here:

bitcoinmagazine.com/guides/how-to-…
3/18 The full article covers @COLDCARDwallet unboxing, initial setup, PIN creation, Firmware update & verification, creating a new wallet, and adding a passphrase. Check the full article if you are setting up your ColdCard for the first time. ImageImageImageImage
Read 18 tweets
Sep 22, 2021
1/18 #Bitcoin blockchain data received by satellite connection instead of an internet connection. Made possible by @Blockstream

A thread on installing & operating a #Bitcoin satellite node on a RaspberryPi. The power of censorship resistance grows stronger everyday.
2/18 This thread is the short version of a more detailed article that is available on the @BitcoinMagazine website here:

Special that you to @igor_auad, his patience & attention to detail were tremendous resources for me.
bitcoinmagazine.com/guides/how-to-…
3/18 I used a RasPi 8GB CanaKit, a Samsung 1TB SSD, & the Sat-IP flat panel satellite antenna available from the @Blockstream store:

All together, this setup was less than $800 USD.

store.blockstream.com/product/blocks…
Read 19 tweets
Aug 27, 2021
1/21 RoninSteel by @RoninDojoUI, a stainless steel backup for securing a #Bitcoin wallet against fire, flood, & prying eyes.
2/21 This thread is the short version of a more detailed article which can be found on the @BitcoinMagazine website here: bitcoinmagazine.com/guides/how-to-…
3/21 Tailored to specifically secure a @SamouraiWallet seed phrase/passphrase, this kit comes with a storage envelope/tamper-evident seals, 2mm thick stainless steel plate, and seed phrase/passphrase obfuscation stickers. Both sides of the plate are used.
Read 21 tweets
Aug 10, 2021
Life gets better when you take action to change your situation.

That action may be different for everyone. The important thing is that you do something.

Here are a few ideas:

Stop being tracked by your mobile device: econoalchemist.com/post/mobile-pr…
Start mining non-KYC #bitcoin at home:

econoalchemist.com/post/home-mini…
Get your #bitcoin off an exchange and into your own control:

econoalchemist.com/post/a-beginne…
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(