I would like your opinion on the cointext FAQ. Specifically around
EDIT: I worked out that it only supports legacy addresses which is a bit shit. Works OK now, but I'm not putting anything other than toy money in it.
EDIT2: Well I wasn't able to steal my own funds by using spoofmytextmessage.com so they are cleverer than I am, but are they cleverer than the black hats?
TLDR= Yes. The reason being is they use a unique identifier associated with the Sim card of the phone to generate send/receive/wallet information. As such, in order to compromise/hack you need physical access to the phone and to copy the sim card. (I'm pretty sure this is using Craig's threshold signatures as well but not certain and can't confirm).
The other weakpoint afaict is you figure out the top secret algorithm
IMHO, this makes the service fairly secure with regard to risk tolerance for most users. I'd feel ok storing <$500 on my phone like that. Especially if they provide an offline/backup option in case my phone/sim card got lost/stolen.
It could be great for adoption and greater competition versus something like venmo.
@Mengerian sorry, I didn't see your post before I completed mine. I think you're right that the super fancy behind the scenes algorithm IS a concern; however, having security partially based off the unique sim code id, I think helps partially mitigate that. I think the super algorithm uses craigs multiplarty threshold stuff but i know some people are trying to put together an audit and to hack the service, specifically the algorithm. Will be interesting. So maybe safe for <$100 holding