-
Notifications
You must be signed in to change notification settings - Fork 2
Verify CLI recovery identity before wallet import #30
Copy link
Copy link
Open
Labels
area: cliCommand-line interface behavior.Command-line interface behavior.area: securitySecurity invariants, hardening, and security-sensitive boundaries.Security invariants, hardening, and security-sensitive boundaries.area: wallet/coreWallet integration and Bitcoin Core boundaries.Wallet integration and Bitcoin Core boundaries.bugSomething isn't workingSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.Resolve, merge, or explicitly defer before the next full adversarial review.
Description
Activity
Metadata
Metadata
Assignees
Labels
area: cliCommand-line interface behavior.Command-line interface behavior.area: securitySecurity invariants, hardening, and security-sensitive boundaries.Security invariants, hardening, and security-sensitive boundaries.area: wallet/coreWallet integration and Bitcoin Core boundaries.Wallet integration and Bitcoin Core boundaries.bugSomething isn't workingSomething isn't workinggate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.Resolve, merge, or explicitly defer before the next full adversarial review.
ms32 walletcould import recovered descriptors before the operator authenticated the recovered seed as the wallet they intended.This is an accident-safety gate, not a malicious-share-tampering defense. A party able to replace a threshold of shares can already learn/spend the wallet and can deliberately manufacture human-scale identifiers.
Required restore evidence, strongest available first:
#57 implements the current release-gate subset for the CLI/library: typed fingerprint plus explicit no-record fallback, with the check enforced before wallet mutation. #28 is the GUI counterpart. #55 remains a separate issue so accident safety is not conflated with malicious-tampering resistance.