-
Notifications
You must be signed in to change notification settings - Fork 2
wallet: Require the recorded fingerprint before import #57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: reviewability-v1
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -171,9 +171,12 @@ wallet should be trusted until initialization completes. | |
|
|
||
| ### 4. Complete the record and store the cards | ||
|
|
||
| Copy the displayed backup identifier, wallet name, Bitcoin Core version, | ||
| master fingerprint, derivation standards, and account number to the wallet | ||
| record. Add the approximate | ||
| Before a freshly created wallet is filled, write the displayed master fingerprint on the | ||
|
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. this sentence is awkward. |
||
| wallet record and confirm that you wrote it down. Fresh creation has no pre-existing | ||
| fingerprint or descriptor to authenticate; `ms32 create --existing` instead uses the | ||
| restore identity gate. Then copy the displayed | ||
| backup identifier, wallet name, Bitcoin Core version, derivation standards, and | ||
| account number to the wallet record. Add the approximate | ||
| creation / earliest-use date. Do not put a descriptor timestamp on a recovery | ||
| card; Core's public descriptor export preserves its stored timestamps. | ||
|
|
||
|
|
@@ -234,16 +237,20 @@ its public wallet data with the separate wallet record. | |
| If you know when the wallet was first used, an earlier Unix timestamp can | ||
| shorten the rescan; `0` remains the safest choice when unsure. | ||
|
|
||
| 5. Select and confirm that wallet. If it is locked, follow the displayed | ||
| 5. Type the master fingerprint from the wallet record. A mismatch stops before | ||
| Bitcoin Core is changed. Press Enter with nothing typed only if there is no | ||
| record; codex32 then shows the recovered fingerprint and what the backup | ||
| identifier says, and asks before restoring. | ||
|
Comment on lines
+240
to
+243
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. ms32 wallet should ask for the fingerprint first, in future PRs: the encrypted descriptor or watch only wallet. This allows the fingerprint to inform error correction. However if a last share has a valid checksum and invalid recovered fingerprint, we don't know which share is wrong (or if the provided fingerprint was wrong) Some of that is mitigated with the fingerprint checksum. We could use a little 1-2 character HMAC with the fingerprint as the secret key or better yet, a digital signature on each share to detect tampering. |
||
| 6. Select and confirm that wallet. If it is locked, follow the displayed | ||
| Bitcoin-Qt Console instructions; codex32 waits and continues automatically. | ||
| It gives Core the master private key, asks Core to create the standard | ||
| account-0 descriptors, scans history, and relocks an encrypted wallet. | ||
| 6. If you need an online watch-only counterpart, keep the restored signer | ||
| 7. If you need an online watch-only counterpart, keep the restored signer | ||
| offline and follow Bitcoin Core v32's | ||
| [offline-signing tutorial](https://github.com/bitcoin/bitcoin/blob/v32.0rc1/doc/offline-signing-tutorial.md) | ||
|
Comment on lines
249
to
250
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. link to master. |
||
| to export and restore the watch-only wallet. Let the online node synchronize, | ||
| then compare the recovered fingerprint, account, policy, addresses, balance, | ||
| and transaction history with the wallet record. | ||
| then compare the account, policy, addresses, balance, and transaction | ||
| history with the wallet record. | ||
|
|
||
| A timestamp of zero safely scans all history and may take time; it belongs in | ||
| the recovery command, not on a paper card. During an emergency recovery, move | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.