Uniform secret structure would prevent wallet fingerprinting #54
Labels
No labels
breaking change
bug
documentation
enhancement
needs discussion
needs implementation
new nut
ready
wallet-only
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
forgejo-admin/nuts#54
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The exact structure of secrets is currently left to the wallets to implement and there is no default value recommended in any NUT. Because not all client libraries build their secrets the same way, a mint can, in theory, eventually learn to fingerprint given libraries that produce certain tokens, lowering the anonymity set for those users.
It might make sense to either:
a. recommend in one of the NUTs that client libraries use a common secret structure
b. enforce a secret size in the protocol for "simple/raw" secrets (not the secrets defined in NUT 10)
Opening this issue for discussion on these ideas.
I propose we all use 32 byte hex strings as secrets!