Do you need SLIP39 when you use a passphrase?

Hello friends!

I want to set up a new wallet but thinking what format to choose. 20 words seems cool but do I need that instead of 12 words Bip39 if I want to use a passphrase? When using a passphrase Seed security is not required, since there’s no money on it. So in case of using 12 words I can store the seed in as man places I want and store a passphrase separately.

And what about plausible deniability with SLIP39, how does it work in this case (without passphrase)?

Also I need my children to be able to recover the wallet.

Plausible deniability I don’t think I may need. I watch on a passphrase as a 2 factor auth like option.

Thank you.

First off, SLIP39 also supports passphrase, if that was not clear.

The purposes of SLIP39 and of passphrase are different, and both are available to you:

  • SLIP39 gives you backup resilience: you can (a) require multiple parties to cooperate when recovering, and/or (b) create redundancy in case some parts of your backup are lost.
  • Passphrase gives you additional layer of protection in case your seed is compromised, or plausible deniability to store multiple wallets on Trezor that are invisible to each other.

This is the wrong way to think about it. Passphrase is an additional layer – by forgoing “seed security”, you are back to one layer. There is almost no advantage to doing it that way:
if you just need one layer, let the seed be that layer.

1 Like

Is it possible to use plausible deniability using only slip39 shares without a passphrase?

From what I’ve learned, slip39 often causes user confusion and is not widely used among hardware wallets.

But yes I can use only 1 set of 20 words of course. Can’t decide what to choose. (sorry can’t edit my prev messages)

Plausible deniability means that you can deny something, and it’s plausible in that nobody can prove you wrong.

E.g., if you have a standard wallet with funds, there is no cryptographic way to prove whether you have another wallet under a passphrase. That other wallet, if it exists, is unlinkable.

SLIP39 is a backup of your seed. There’s nothing that you could plausibly lie about here: you have a backup of a seed, that means that the backup can be recovered. I have no idea what sort of “plausible deniability” are you looking for here.

1 Like

Plausible deniability with slip39 I mean this - can you say that you have only one 20 word list with crypto on this like with multisig schemes when you have for example 3 seed phrases and 3 wallets, and you can have bitcoin on each seed also. Hope it’s clear.

No. That’s not how it works.

You need a specific number of shares (20-word parts) to recover the wallet.

If you have a 3-of-5 scheme, that means that Trezor generates 5 shares and you can use any 3 to recover.

Importantly:

  • You have to have at least 3 to recover. One (or two) shares doesn’t make a wallet, it makes nothing. Trezor will say “give me two more”.
  • Any 3 you choose always recover the same wallet. If the shares are ABCDE, the wallet ABC is the same as BCD is the same as ACE.

The purpose of the design is:

  1. sharding, that is, you need more than one to recover, and
  2. redundancy, that is, if you lose some shares, you can still recover with the rest.

You can’t combine shares at random to get a wallet. You need the right combination only.

Plausible deniability was never the goal here – the opposite, actually, the goal is a scheme that is difficult to mess up. So if you recover something, you can be sure that it’s the right thing.

1 Like

Thank you, now it’s clear. Chat GPT said stupid stuff about Slip39 so I decided to ask here.

1 Like