{"id":429,"date":"2014-05-05T10:49:38","date_gmt":"2014-05-05T18:49:38","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=429"},"modified":"2014-05-05T23:21:51","modified_gmt":"2014-05-06T07:21:51","slug":"piperwallet-first-impressions","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=429","title":{"rendered":"PiperWallet First Impressions"},"content":{"rendered":"<p>So I just got my PiperWallet. For those of you not yet familiar with it the <a href=\"https:\/\/github.com\/piperwallet\">PiperWallet<\/a> is an open-source\u00a0hardware bitcoin wallet based <a href=\"https:\/\/electrum.org\/\">Electrum<\/a> running on a <a href=\"http:\/\/www.raspberrypi.org\/\">RaspberryPi<\/a>\u00a0paired with a built in <a href=\"http:\/\/www.adafruit.com\/products\/597\">thermal printer<\/a>\u00a0in what looks like a 3D printed chassis.<\/p>\n<p>The basic idea is that managing cold wallets is hard and it doesn\u2019t have to be.<\/p>\n<p>Even though I have only started to play with the device overall I am impressed. Here are my initial observations:<\/p>\n<ol>\n<li>It was packaged well considering the volume in which they are produced;<\/li>\n<li>The quality of the casing is also good considering the volume;<\/li>\n<li>The cut outs are a little rough and are larger than the connectors they expose;<\/li>\n<li>The primary \u201cindicator LED\u201d that is used to show\u00a0that the device is booting is not terribly bright;<\/li>\n<li>Without reading the instructions (or waiting a sufficiently long time) it\u2019s not \u00a0obvious when the device is ready;<\/li>\n<li>The print button LED is bright and of excellent quality;<\/li>\n<li>There is no positive feedback when the print button is pressed.<\/li>\n<\/ol>\n<p>So far I am happy with the purchase though I need to do some more playing with it before I make any final conclusions.<\/p>\n<p>With that said here are the things I think I would change if it were my product:<\/p>\n<ol>\n<li>Make the serial numbers on the paper wallets randomly generated; you un-necessarily leak information by using monotonically generated serials;<\/li>\n<li>Add tamper evident seals to the casing so that if the device is opened during shipping it is obvious;<\/li>\n<li>Add tamper evident seals or \u201cplugs\u201d over the ports exposed on the device, possibly even dummy plugs with seals so its clear nothing happened to the device as part of shipping;<\/li>\n<li>Add per-device fixed wallet keys to be used as a serial number to the back of each case (there is a wallet address but I believe this is an address of the Piper team);<\/li>\n<li>Use per device passwords shipping them on a form similar to the one I provided <a href=\"http:\/\/unmitigatedrisk.com\/?p=406\">here<\/a>;<\/li>\n<li>Replace the indicator LED with one with a similar brightness and quality to that used in the \u201cprint button\u201d;<\/li>\n<li>Add a small LCD display that can be used to provide real-time feedback and status so it\u2019s easier to use when headless;<\/li>\n<li>In the documentation included have the steps to verify what software is running on the device along with hashes to do so.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>So I just got my PiperWallet. For those of you not yet familiar with it the PiperWallet is an open-source\u00a0hardware bitcoin wallet based Electrum running on a RaspberryPi\u00a0paired with a built in thermal printer\u00a0in what looks like a 3D printed chassis. The basic idea is that managing cold wallets is hard and it doesn\u2019t have [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[104,3,4],"tags":[102,110],"class_list":["post-429","post","type-post","status-publish","format-standard","hentry","category-bitcoin-2","category-security","category-thoughts","tag-bitcoin","tag-piperwallet"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=429"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/429\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}