Skip to content

doc: Add unshared secret generation to wallets.md - #71

Draft
BenWestgate wants to merge 3 commits into
BlockstreamResearch:masterfrom
BenWestgate:57-wallet-add-doc-for-generating
Draft

BenWestgate wants to merge 3 commits into
BlockstreamResearch:masterfrom
BenWestgate:57-wallet-add-doc-for-generating

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Oct 17, 2025 •

Copy link
Copy Markdown
Contributor

Closes #64

This is a draft of unshared secrets generation support.

Summary: Updated to discourage weird bitlengths, improve error correction handling. Added details on generation support for codex32 secrets.

Guidance for codex32 share sets generation can come in a later PR as it will depend largely this seed export guidance.

I covered string display and confirmation, from my experience designing these and receiving user feedback.

Confirm section presents two methods depending on keyboard available:

  1. Full-verification method I used in Bails that is very easy and well liked by beta testers, and
  2. Partial-verification method Blockstream used in Jade, borrowed near verbatim from: https://github.com/Blockstream/Jade/blob/690c8b1c5f9ccaf18954111a6ee8e124f2b75eec/main/process/mnemonic.c#L269-L398
  • Essentially, change only word-list and Jade can display and confirm 128-bit codex32 strings just as well as bip39.

Missing/TBD:

  • BIP85 app (if it merges).
  • Reference GUI
    • I have had for years a complete reference Gtk GUI of the "Full confirm" dialog, Bails uses it. I'll try to package that with the display and import views to make a PyPI codex32-gui I package for devs to play with.
  • Reference CLI/Library
    • I wrote a codex32 PyPI library, my apologies if I was not supposed to take this name. The implementation is at least as clean as the rust in this repo and passes all BIP93 test vectors.

Updated import support specifications for wallet seed lengths and error correction handling. Added details on generation support for codex32 secrets and share sets.
@BenWestgate BenWestgate changed the title WIP: Revise wallet import and add generation specifications WIP: Add generation specifications Oct 17, 2025
Clarified wallet behavior for invalid headers and checksums, improved error correction guidance, and refined display and confirmation processes for codex32 strings. Removed SSS section for brevity.
@BenWestgate
BenWestgate marked this pull request as ready for review October 19, 2025 03:23
@BenWestgate BenWestgate changed the title WIP: Add generation specifications doc: Add unshared secret generation to wallets.md Oct 22, 2025
Refine guidance on generating unshared secrets and update codex32 secret backup process. Improve clarity on identifier policies and human-readable parts.
@BenWestgate

Copy link
Copy Markdown
Contributor Author

@roconnor-blockstream This is ready for review.

@roconnor-blockstream

roconnor-blockstream commented Oct 24, 2025 •

Copy link
Copy Markdown
Collaborator

I don't know if I'm quite ready to completely abandon 160-bit and 192-bit seeds just yet. Maybe I could be convinced.

@BenWestgate

This comment has been minimized.

@BenWestgate
BenWestgate marked this pull request as draft November 25, 2025 18:55
@BenWestgate

This comment has been minimized.

@BenWestgate

This comment has been minimized.

@stachrom

stachrom commented Oct 1, 2026

Copy link
Copy Markdown

@apoelstra what holds you back?

@BenWestgate

Copy link
Copy Markdown
Contributor Author

Well, first this is marked as draft, and had a lot of outdated comments about the permitted string lengths that were just recently standardized in BIP93.

The only thing I have to say about those comments is unshared secrets may use a BIP32 fingerprint as a default ID, a random or user selected ID SHOULD be distinct from all other seeds.

Shared strings SHOULD NOT use any identifier derived from the secret as it weakens SSS k-1 information theoretic security to computational and the 20-bit oracle could substantially help an attacker with ~k-0.75 shares.

I still like suggesting may use CRC padding, especially for unshared secrets.

I left it out of the "ms" profile for the bip85 app-93 to keep the review and implementation simple.

I can update this this week.

There have been some very not to spec unreviewed implementations of codex32 generation recently so it's becoming urgent we finish this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Suggest standard implementation for electronic share set generation

3 participants