​Are your coins safe? "Bepal" believes that it is more important to cultivate the security awareness of digital asset users than selling cold wallets
郝方舟
2018-03-08 00:48
本文约1840字,阅读全文需要约7分钟
Last night, the Binance trading system malfunctioned, suspected to be hacked, and the entire digital currency plummeted​.

Recently, there are more and more friends who "hold currency" around me, and I have also received some questions about "where is the currency safe?" At present, the relatively recognized security ranking in the "circle" is: cold wallets > hot wallets and large exchanges > "Xiaoxin" exchanges.

Last night, the Binance trading system malfunctioned, suspected of being hacked, and the digital currency plummeted across the boardLast night, the Binance trading system malfunctioned, suspected of being hacked, and the digital currency plummeted across the boardThe Bitfinex exchange also had 120,000 bitcoins (valued at about $75 million at the time) stolen due to security breaches in hot wallets. Manufacturers of hardware wallets that I have contacted recentlyBepalIt is believed that the security awareness of digital asset users is the most effective "anti-theft door" at this stage.

First introduce the new products of Bepal.

In January, Bepal upgraded iteratively on the basis of version 1.0 cold wallet Bepal Basic, and launched it for C-end usersBepal Pro, a hardware cold wallet that protects private keys and supports multiple currencies

Digital currencies supported by Bepal

BepalThe safety principle is the separation of cold and hot: As a non-networked hardware device, the cold wallet corresponds to a unique account, and only stores transaction signatures, and cannot complete the transaction function independently; the hot wallet constructs and broadcasts transactions, and monitors account information;Encrypted communication between hot and cold via QR code, to complete the addition and update of currencies, the withdrawal and deposit of digital currencies.

Compared with chip-type cold wallets that need to be used in combination with computers, Bepal is based on mobile devices, which is more convenient for interaction and operation.

When the user creates an account, Bepal will randomly generate the master, private key and password (mnemonic) using the BIP44 rule. Users can hand-copy on the attached code card.As long as the user keeps the password properly, even if the wallet is lost and the company runs away, the digital assets can be restored to a new device or other wallets with one click. At the same time, QR code communication is not like wifi, bluetooth and other signals that may be intercepted and cracked during transmission

If the device falls into the hands of hackers for a long time and encounters malicious hardware intrusion (Hardware Hacking), the user will also be at risk of being stolen. Therefore, once the device is lost, the user should restore the account and transfer assets through other wallets as soon as possible.

Therefore, Bepal's next-generation products may adopt new charging technology and interaction methods, and enhance the security level with a new chip encryption scheme.

However, greater security risks come from user operations and security awareness beyond technology. Recalling the Internet age, when bank tellers teach customers how to use online banking at outlets, some old people still ask the tellers to set up a login password (usually 123456), and then copy it on the back of the bank card, or reply the verification code to a fraudulent text message.

Bepal initially thought that only "Xiaobai" could not figure out the hot and cold wallets and address private keys, but later found that many "coin circle bigwigs" and corporate customers were also "confused" at the operational level. Therefore, before product promotion, users will be educated with a more lively "writing style" (IP, emoticons and four-frame comics).

COO Fan Xue and I talked about some safety tips, including:

  1. Do not send photos of the QR code on the cold wallet to others;

  2. Do not hand over your private key or seed phrase to anyone;

  3. Don't believe in "customer service", "upgrade", or any "substituting operation" (Bepal only publishes announcements through the official website and APP every time it is updated);

  4. In-depth understanding, in the digital currency world, there is no option to "retrieve password"...

From the perspective of the industry, the barriers of wallet manufacturers lie in technology. Only through a large number of tests, continuous discovery and repair of system loopholes, and long-term maintenance of "zero accidents" can a safe brand image be established. According to reports, Bepal will also partially open source in the near future to accept verification from more professional users.

Another large cold wallet manufacturer in China"Kushen" received tens of millions of US dollars in Series A financing in December last year. According to public information, Yuan Dawei, the founder and CEO of "Koshen", was once the co-founder of Huobi.com, and Huobi is also an angel round investor of "Koshen", and the two parties have cooperated closely. In addition to hardware manufacturing, Bepal will focus more on security technology and enterprise solutions.

Bepal intends to open cooperation with mainstream hot wallets in the market: hot wallet manufacturers do not need to develop their own cold wallets, and their existing customers can directly use Bepal cold wallets by scanning the code. Co-cultivating and opening up the market is also the correct "posture" for startups in the early stages of the market.

The official website of Bepal Pro is priced at 2980 yuan. In this regard, my first reaction is that small speculators who "speculate in the short term" may be unwilling to insure their "several coins" because they are lucky about "the platform running away and their wallets being hacked". But I ignored the centralized procurement needs of "big customers", such as blockchain project teams, exchanges, mining pools, etc. that hold a large number of coins and store coins for a long time.

Bepal's revenue is mainly to B, The team had frequent contact with mining pools, currency circles, and chain circles during the technical testing period. Its angel round investors have more external resources, and the "circle" itself is not large, so the acquisition of customers is very accurate. Since the launch of Bepal Pro, nearly 3,000 orders have been placed. In addition, Baofeng signed a contract with Bepal as a sales channel. In order to prevent risks such as Trojan horse implantation and phishing attacks, Bepal only cooperates with strong brands for sales, and does not take the route of "wide distribution channels".

The Bepal team has more than 60 people, mainly based on technology, has rich experience in technology research and development, and some members come from Bitcoin mining poolsF2Pool fish pond. The founder Hu Yuanquan is a "white hat" who is active in the network security circle. Since 2015, he has foundedShanren TechnologyI am Hao Fangzhou, and I am concerned about high-quality projects related to the blockchain. If you add WeChat nooxika, please note the company + name + reason.

I am Hao Fangzhou, and I am concerned about high-quality projects related to the blockchain. If you add WeChat nooxika, please note the company + name + reason.

郝方舟
作者文库