I want to set up a new wallet but thinking what format to choose. 20 words seems cool but do I need that instead of 12 words Bip39 if I want to use a passphrase? When using a passphrase Seed security is not required, since there’s no money on it. So in case of using 12 words I can store the seed in as man places I want and store a passphrase separately.
And what about plausible deniability with SLIP39, how does it work in this case (without passphrase)?
Also I need my children to be able to recover the wallet.
Plausible deniability I don’t think I may need. I watch on a passphrase as a 2 factor auth like option.
First off, SLIP39 also supports passphrase, if that was not clear.
The purposes of SLIP39 and of passphrase are different, and both are available to you:
SLIP39 gives you backup resilience: you can (a) require multiple parties to cooperate when recovering, and/or (b) create redundancy in case some parts of your backup are lost.
Passphrase gives you additional layer of protection in case your seed is compromised, or plausible deniability to store multiple wallets on Trezor that are invisible to each other.
This is the wrong way to think about it. Passphrase is an additional layer – by forgoing “seed security”, you are back to one layer. There is almost no advantage to doing it that way:
if you just need one layer, let the seed be that layer.
Plausible deniability means that you can deny something, and it’s plausible in that nobody can prove you wrong.
E.g., if you have a standard wallet with funds, there is no cryptographic way to prove whether you have another wallet under a passphrase. That other wallet, if it exists, is unlinkable.
SLIP39 is a backup of your seed. There’s nothing that you could plausibly lie about here: you have a backup of a seed, that means that the backup can be recovered. I have no idea what sort of “plausible deniability” are you looking for here.
Plausible deniability with slip39 I mean this - can you say that you have only one 20 word list with crypto on this like with multisig schemes when you have for example 3 seed phrases and 3 wallets, and you can have bitcoin on each seed also. Hope it’s clear.
You need a specific number of shares (20-word parts) to recover the wallet.
If you have a 3-of-5 scheme, that means that Trezor generates 5 shares and you can use any 3 to recover.
Importantly:
You have to have at least 3 to recover. One (or two) shares doesn’t make a wallet, it makes nothing. Trezor will say “give me two more”.
Any 3 you choose always recover the same wallet. If the shares are ABCDE, the wallet ABC is the same as BCD is the same as ACE.
The purpose of the design is:
sharding, that is, you need more than one to recover, and
redundancy, that is, if you lose some shares, you can still recover with the rest.
You can’t combine shares at random to get a wallet. You need the right combination only.
Plausible deniability was never the goal here – the opposite, actually, the goal is a scheme that is difficult to mess up. So if you recover something, you can be sure that it’s the right thing.