Appendix D

The Fenton Tests

We will go one by one through each Fenton test and provide a response discussing whether this protocol passes the test. We have selected the Fenton Tests because it's a bar to reach set by a person who is passionate about the subject coming from a holistic view. HWW vendors will document all the ways their device protects you but might miss documenting ways their device is prone to attack or user error. We don't want a solution that is better than HWW, we want a solution that solves all the attack vectors from all but the rarest adversaries.

We are strictly defending the security of the level-4 wallet against these Fenton tests and we believe our level 1, 2, 3 wallets will fail Test 3 and 5.

Test 1 - “Tell your next of kin to retrieve your coins as if you had died. They are only allowed to use the info they have now. No new note or instructions allowed- if you died today they wouldn’t have those instructions either. See how the test works.”

Response: follow the Appendix A letter to your heir(s) and install Bluewallet on their phone. Teach them to buy, sell or spend Bitcoin at least once a month to keep their mind engaged with the technology. Test passed!

Test 2 - “Put your phone down and pretend that it, your PC and every single thing in your home / office is destroyed. Now retrieve your coins. Remember - no use of your phone or anything from your home - no paper, notes, nothing.”

Response: this is such a thought provoking test. A cryptosteel capsule should survive a house fire and some localized flooding. It won't survive a bomb or a Katrina like city-wide flood. But this test isn't about a destroyed city. It's about a destroyed home AND office simultaneously. Yet, we recommended you put your level-4 seed A (L4SA) in your home with a copy in your office locker/safe. Level-4 seed B (L4SB) is with family member F1 and with Bank 1 safety deposit box. To pass this test, if you think your office can be destroyed at the same time as your home, then you could give your sibling L4SB and put a copy of L4SA in Bank 1 safety deposit box. Obviously, if you can get safety deposit boxes at more than one bank that is ideal but access to safety deposit boxes varies based on where you live. The take away is to modify where you store L4SA and L4SB if your home and office might be destroyed simultaneously. I consider this a pass.

Test 3 - “Stop what you are doing & assume 2 or more armed attackers are now at your main premises. Assume they have disabled means for help & assume they will find a safe if you have one. If they threaten violence against you how exactly do you deal with this? What can they get?”

Response: as stated earlier they will get your level 1, 2, 3 wallets because we don't trust ourselves to keep secrets from violent attackers. A seasoned Bitcoiner will likely take advantage of having two passwords inside the Bluewallet. The regular password and a plausible deniability password that opens a different wallet. I recommend you do this on your phone A such that either your level-3 wallet is opened or your level-4 seed A wallet is opened. Because you cannot trust yourself to put the right password in under duress. Either way you will not be able to spend from your level-4 wallet under duress because seed B is not at home and requires traveling to a different location and getting permission from someone to enter that premises that you can inform you are under duress and request they call the police. Keep the vast majority of your money on the level-4 wallet so the attackers don't get any life changing amounts. I consider this a pass for test 3.

This raises a missing test: “you have temporarily gone insane and you decide to burn your Bitcoin, sell your Bitcoin or import your keys into some scam wallet for a promise of a shitcoin air drop.”

Response: this is why you need your level-4 wallet to require leaving your home and interacting with a family member or banker who can deduce you are mentally unwell. People trust themselves too much and are highly prone to panic sell their full stack under a manic episode induced by a government ban or a developer rage quit.

Test 4 - “Assume that over a period of 3 weeks you suffer from illness, amnesia, dementia or extreme trauma which causes you to forget everything about your current setup. How do you or your loved ones / living assistants rebuild and understand your storage system?”

Response: because our model doesn't require memorized passwords for recovery this is essentially a repeat of Test 1. Again, follow the Appendix A letter to your heir(s) and install Bluewallet on their phone. Teach them to buy, sell or spend Bitcoin at least once a month to keep their mind engaged with the technology. Be specific about where your cryptosteel capsules are hidden in your letter. Test passed!

Test 5 - “You speak misinformation, are a political enemy or are accused of a crime. The government gets a search warrant for your office, home, bank & safe deposit box. Assume they will find any 12 or 24 word pass phrase or private key on the premises. Can an agent sweep it?”

Response: I think this is the toughest test. We've relied on 4 locations and in this test the government has seized our devices and seeds from our home, office and bank safety deposit box! We are left with family and friends to stash our seeds and we don't want to take on any collusion risk because that's a higher risk. Unfortunately, under this model if they get seed A at your home and bank safety deposit box then you don't have seed A. If they get seed A in your home and seed A in your office and seed B in your bank safety deposit box then they have your funds.

If you have seed A in a cloud password manager and can recover it later using memory and a new device then you could pass this test.

Let's summarize our level-4 hiding spots and what is hidden there to pass all 6 Fenton tests:

H1 - at home hiding spot for your:
  • level-4 seed A cryptosteel capsule (Superman seed)
H2 - at home hiding spot for your:
  • level-4 phone A (Superman phone)
H3 - bank safety deposit box
  • level-4 seed A cryptosteel capsule (Superman seed)
H4 - office safe/work locker
  • level-4 seed A cryptosteel capsule (Superman seed)
Cloud1 - a cloud based password manager
  • level-4 seed A that's recoverable with a new device and your memory.
F1 - a family member's home
  • level-4 phone B (Kryptonite phone)
  • level-4 seed B cryptosteel capsule (Kryptonite seed)
F2 - another family member's home
  • level-4 seed B cryptosteel capsule (Kryptonite seed)

Test 6 - “There is extreme political turmoil in your country and you have 24 hours to pack your bags & move to another country. Assume banks/ safe deposit locations are closed. You won’t be able to return to your country. Can you bring your coins and access them in a new country?”

Response: you have level-4 phone/seed A at home and level-4 phone/seed B in the same city at family member F1's home. You take both with phones and seeds with you to your new country. Test passed!

Wealthy people might have a second home in another country with copies of level-4 seed B. So, they can take seed A from home in the turmoil country to the home in safety country where seed B is also located.