{"id":770,"date":"2018-07-04T10:33:26","date_gmt":"2018-07-04T08:33:26","guid":{"rendered":"http:\/\/www.mariusb.net\/blog\/?p=770"},"modified":"2021-12-16T15:06:24","modified_gmt":"2021-12-16T13:06:24","slug":"cryptocurrencies-security-mnemonic-and-2fa","status":"publish","type":"post","link":"https:\/\/www.mariusb.net\/blog\/2018\/07\/cryptocurrencies-security-mnemonic-and-2fa\/","title":{"rendered":"CryptoCurrencies &#8211; Security, Mnemonic and 2FA"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-771 size-medium alignleft\" src=\"https:\/\/i0.wp.com\/www.mariusb.net\/blog\/wp-content\/uploads\/2018\/07\/two_factor_authentication.png?resize=300%2C168\" alt=\"\" width=\"300\" height=\"168\" srcset=\"https:\/\/i0.wp.com\/www.mariusb.net\/blog\/wp-content\/uploads\/2018\/07\/two_factor_authentication.png?resize=300%2C168&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.mariusb.net\/blog\/wp-content\/uploads\/2018\/07\/two_factor_authentication.png?resize=768%2C430&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.mariusb.net\/blog\/wp-content\/uploads\/2018\/07\/two_factor_authentication.png?resize=1024%2C573&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.mariusb.net\/blog\/wp-content\/uploads\/2018\/07\/two_factor_authentication.png?w=1280&amp;ssl=1 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p class=\"p1\">In my <a href=\"http:\/\/www.mariusb.net\/blog\/2018\/06\/cryptocurrencies-no-keys-no-coins\/\">previous post<\/a>, I wrote about the importance of owning your own keys instead of keeping your coins in an online wallet or on an exchange.<span class=\"Apple-converted-space\">\u00a0 <\/span>Owning your own keys brings with it the responsibility of keeping it safe and out of the hands of other people.<span class=\"Apple-converted-space\">\u00a0 <\/span>To do this it is important to have strong security in protecting your assets and investments.<\/p>\n<p class=\"p1\">There are mainly 3 items that come into play here:<\/p>\n<ul>\n<li class=\"p2\">Your password or sometimes called a passphrase.<\/li>\n<li class=\"p2\">Mnemonic words &#8211; these are between 12 and 24 randomly chosen words.<\/li>\n<li class=\"p2\">Two Factor Authentication (2FA)<\/li>\n<\/ul>\n<p class=\"p3\"><b>Password \/ Passphrase<\/b><\/p>\n<p class=\"p1\">Most if not all wallets use a password or passphrase to give you access to your funds and more importantly to encrypt the wallet information when it stores it on your device.<span class=\"Apple-converted-space\">\u00a0 <\/span>It is important to have a strong password that you can remember.<span class=\"Apple-converted-space\">\u00a0 <\/span>I usually use some phrase that is fairly long, at least 20 characters and I include characters like \u201c!@#$%^&amp;*-_\u201d in my passphrase.<span class=\"Apple-converted-space\">\u00a0 <\/span>If you scared that you will forget your password or passphrase then write it down on a piece of paper and store it safely in a safe.<span class=\"Apple-converted-space\">\u00a0 <\/span><b><i>Do not store it on some online storage like Dropbox and\/or Google Drive.<\/i><\/b><\/p>\n<p class=\"p3\"><b>Mnemonic or otherwise know as a seed<\/b><\/p>\n<p class=\"p1\">A\u00a0mnemonic phrase,\u00a0mnemonic recovery phrase\u00a0or\u00a0mnemonic seed\u00a0is a list of words which\u00a0store\u00a0all the information needed to recover a Bitcoin wallet. Wallet software will typically generate a mnemonic backup phrase and instruct the user to write it down on paper.<span class=\"Apple-converted-space\">\u00a0 <\/span>Best is to make several copies of it and store it in different places.<span class=\"Apple-converted-space\">\u00a0 <\/span>Also good to laminate it since it might fade over time if not protected. If the user&#8217;s computer breaks or their hard drive becomes corrupted, they can download the same wallet software again and use the paper backup to get their bitcoins back.<\/p>\n<p class=\"p1\">Anybody else who discovers the phrase can steal the bitcoins, so it must be kept safe like jewels or cash. For example, it must not be typed into any website. <b><i>Also do not ever store it somewhere on your computer or any online storage like Dropbox and\/or Google Drive.<\/i><\/b><\/p>\n<p class=\"p1\"><b>Two Factor Authentication (2FA)<\/b><\/p>\n<p class=\"p1\">Two-factor authentication\u00a0(also known as\u00a02FA) is a type (subset) of multi-factor authentication. It is a method of confirming a user&#8217;s claimed identity by utilizing a combination of\u00a0two\u00a0different factors: 1) something they know, 2) something they have, or 3) something they are.<\/p>\n<p class=\"p1\">A good example of two-factor authentication is the withdrawing of money from an\u00a0ATM; only the correct combination of a\u00a0bank card\u00a0(something that the user possesses) and a PIN (personal identification number, something that the user knows) allows the transaction to be carried out.<\/p>\n<p class=\"p1\">The most common use is when one logs into a website with a Username and Password and are then presented with another screen requesting the user to enter a code.<span class=\"Apple-converted-space\">\u00a0 <\/span>One way is that this code is sent to the user\u2019s registered email address or more commonly his cellphone via SMS. <span class=\"Apple-converted-space\">\u00a0 <\/span>Another way and the more preferable way is that the user uses a code that he gets from an application on his cellphone.<span class=\"Apple-converted-space\">\u00a0 <\/span><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.google.android.apps.authenticator2&amp;hl=en_ZA\">Google Authenticator<\/a> is one such application but the one that I prefer is <a href=\"https:\/\/authy.com\/\">Authy.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my previous post, I wrote about the importance of owning your own keys instead of keeping your coins in an online wallet or on an exchange.\u00a0 Owning your own keys brings with it the responsibility of keeping it safe and out of the hands of other people.\u00a0 To do this it is important to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[163,171],"tags":[181,164,169],"class_list":["post-770","post","type-post","status-publish","format-standard","hentry","category-bitcoin","category-cryptocurrencies","tag-2fa","tag-bitcoin","tag-cryptocurrencies"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1SHVw-cq","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/posts\/770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/comments?post=770"}],"version-history":[{"count":4,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/posts\/770\/revisions"}],"predecessor-version":[{"id":859,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/posts\/770\/revisions\/859"}],"wp:attachment":[{"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/media?parent=770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/categories?post=770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mariusb.net\/blog\/wp-json\/wp\/v2\/tags?post=770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}