Uniform secret structure would prevent wallet fingerprinting #54

Closed
opened 2023-09-30 18:17:40 +00:00 by thunderbiscuit · 1 comment
thunderbiscuit commented 2023-09-30 18:17:40 +00:00 (Migrated from github.com)

The exact structure of secrets is currently left to the wallets to implement and there is no default value recommended in any NUT. Because not all client libraries build their secrets the same way, a mint can, in theory, eventually learn to fingerprint given libraries that produce certain tokens, lowering the anonymity set for those users.

It might make sense to either:
a. recommend in one of the NUTs that client libraries use a common secret structure
b. enforce a secret size in the protocol for "simple/raw" secrets (not the secrets defined in NUT 10)

Opening this issue for discussion on these ideas.

The exact structure of secrets is currently left to the wallets to implement and there is no default value recommended in any NUT. Because not all client libraries build their secrets the same way, a mint can, in theory, eventually learn to fingerprint given libraries that produce certain tokens, lowering the anonymity set for those users. It might make sense to either: a. recommend in one of the NUTs that client libraries use a common secret structure b. enforce a secret size in the protocol for "simple/raw" secrets (not the secrets defined in NUT 10) Opening this issue for discussion on these ideas.
callebtc commented 2023-10-13 18:07:34 +00:00 (Migrated from github.com)

I propose we all use 32 byte hex strings as secrets!

I propose we all use 32 byte hex strings as secrets!
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
forgejo-admin/nuts#54
No description provided.