Thank you very much for your proposal. It looks like signers might soon be required with BCE 4.0 around the corner.
I understand that
is necessary to provide the exchange with a reliable service.
But I’m on the fence regarding
to achieve that goal, because of the combination of VPS and confidential data, such as wallets containing important keys.
It’s for that reason I run NuBot not on a VPS, but on a RaspberryPi under my control instead - and with the keys on it, “only” the liquidity broadcast could be messed up (as long as the keys are valid).
I know that VPS are convenient. I have several of them. But I’m hesitant using them for confidential tasks.
You just don’t have control over the hardware.
This includes physical access as well as the harddisks, the RAM - the whole VPS host.
I’m aware that my RaPi can get stolen and that the wallet files can get lost to others this way.
But it will be hard to get both the wallet files AND the wallet passphrase.
The VPS can’t protect you from losing both, if an evil administrator wants to have them.
BCE signer keys are the keys to money!
This sounds pretty much paranoid, but if BCE becomes as successful as some think, the signers are the number one attack vector.
To reduce the attack surface, VPS should be avoided.