Self-Custody

We need to talk about self-custody
Digital asset self-custody at first seems trivial, until we think carefully about it.
In the 1990s and 2000s, I worked in computer operations, and backups and archives were part of my job. I thought I knew everything required about these tasks, but I didn’t. It is so easy to under-think it.
The initial challenge is to always be able to recover all (actually most) of your company’s data, day-to-day, and in the case of a significant disaster. This is where (organisational) self-custody comes in.
Multiple Backups
New to the profession, I quickly learnt never to trust ‘media’ (tapes or disks). The industry standard, if one has a planned data ‘save and restore’ operation, say, upgrading the operating system, is to take multiple full archives of the data before the operation, so if one of the instances of the media proves faulty during restore, there is another copy. I learnt that using multiple technologies (backup applications) as well also makes sense. The media may be faulty, but so also might be the software that does the save and restore.
Off-site Backups
Every organisation I worked for also used off-site backups. I have had cause to use this recovery service only occasionally, but when you need it, you appreciate how critical it is. It is also used to recover data from a disaster.
Standards and Best Practices
A lot of these practices were formulated in the 1990s in the Information Technology Infrastructure Library (ITIL). Of particular benefit are the understanding of recovery point objective (RPO) and recovery time objective (RTO). The whole discipline of Business Continuity and Disaster Recovery evolved. Organisations that embraced ITIL lifted their game.
Still, achieving 100% discipline is hugely difficult, and many organisations, large and small, made mistakes. When they did, wherever possible, corporate ensured nobody got to know; loss of confidence in the business was to be avoided at all costs.
Root Cause
I believe the root cause for all of the mistakes comes down to the same thing - underestimating the challenge of self-custody and therefore not being sufficiently diligent and disciplined.
Information Loss Protection
With the proliferation and accessibility of technologies such as USB media, corporate email, and cloud computing, the complementary risk to one’s data became more important. Can someone access your corporation’s data?
This is the second challenge - to always ensure that there can be no unauthorised access to the corporation’s data.
Again, this is not as straightforward as it seems. We live in a world with continually increasing surveillance and data capture, and an increasing disconnect between the organisation and those who manage its data.
From the viewpoint of computer operations, we have seen more emphasis given to physical security, data encryption, and digital rights management. Still, corporate data loss is a huge problem that seems to be increasing.
Enter BitCoin
Bitcoin was and is a triumph of bringing together a collection of ideas and technologies to disrupt a fundamental human interaction - that of money and the direct digital transfer of it. To achieve this, it pushed the boundaries in so many ways. 18 years later, I still find it incredible.
One of its key innovations was the self-custody of digital assets (Bitcoin). This is the fundamental way Bitcoin is held (as a self-custodied digital bearer instrument). Indeed, this is the intent of the technology - to be able to hold it and pay with it, without a centralised party being involved. Only later were custodians introduced; first, (centralised) cryptocurrency exchanges would naturally hold your crypto before you take custody of it. Later, for financial services, dedicated custodians would be introduced.
Bitcoin Self-Custody
Since with Bitcoin one can (and perhaps should) self-custody it, that brings with it all the same challenges that corporate computer operations have.
The Hard Truth
The consequence of loss, either due to revealing your passphrase to others or losing your pass phrase altogether, is just as great as for the corporation that loses its data. This does occur quite often, both with corporate data loss and with Bitcoin self-custody loss.
Hidden Cost of Bitcoin Custody
So, this is the fundamental shortcoming of the Bitcoin ‘solution’ - we require everyone who uses it to achieve the same level of self-custody expertise that large organisations require of their dedicated operations staff, and large organisations fail in this regard all the time. That’s a big ask, and technology is not helping, and the help it can give is limited.
Further Study
Once I figured out this challenge with Bitcoin self-custody, I decided I would learn all about it. I came to realise it is an almost insurmountable problem with the original Bitcoin solution. Bitcoin advocates (maximalists) understandably do not like this point of view. It was a deal breaker for me and caused me to lose interest in holding crypto.
I have found one excellent video presentation on the issue that lays out the concerns and treatments better than any other. It is the “Jameson Lopp’s masterclass (Chief Technology Officer at CASA) from Hal Finney Room - Palazzo dei Congressi, Lugano - Friday 28th October 2022”. This is an excellent place to start if you want to consider this topic further.