Compared to for example SeedSigner with a hypothetical FROST implementation with paper backups, what would be the benefit of this device? Spend limits sound cool, but they can’t be securely enforced without a SE. And not a simple PIN-protected secure memory, but one that can run arbitrary code. Also, how is key reconstruction handled when changing for example the quorum size?

Replies (1)

It would be hard to get FROST to work on seed signer because it’s stateless. I know a trick that *might* make it possible. So the main advantage of frostsnap is that it exists! Yes spending limits require secure hardware that never leaks its secret. Changing quorum size just means making a new sharing of the secret and everyone deleting their old shares. You can do this without reconstructing the secret.