Repository
This proposal will target the main entrypoint(wallet) of the steem blockchain: https://github.com/steemit/condenser.
This can also be applied/extended to the other wallets/frontend like:
- https://github.com/steemit/steem
- https://github.com/steemit/steem-js.
- https://github.com/busyorg/busy
- https://github.com/steemit/steemconnect
Note: I know it is not usual per utopian rules to link multiple repositories, but it would have been silly to make the same post again per repository. The point of this article is to start the discussion and find people who might be interested in working on that. I had the idea a while ago but could not find time/funds/motivation.
Benefits
Steem is 2 years old and has, since it is a social network, a much diverse community than any other blockchain. Yet Steemians are required to deal securely with 4 different keys(5 keys if you are a witness). The introduction of steemconnect mitigates the issue but can we trust the non technical savvy users to not use their password or owner key for everything? There is a constant stream of fake websites, applications, rogue links trying to steal users' funds. We can improve the overall security of the blockchain with the support of hardware wallets.
Proposal
This proposal is focused on the wallet and key management. It is about adding hardware wallet support for the steem blockchain. We want to give a high level layout of the solution(see the different modes proposed).
Good Points: steem uses the same cryptography as Bitcoin, thus most of the code is already there (never roll out your own crypto). As long as we can generate the keys, the various APIs can do the rest of the work.
Bad Points: steem derives the keys from the seed/password differently:
secret = SHA256( account + role + password )
We might need to implement this derivation for compatibility reasons and we need this secret to be extractable (see for instance the mode low). There is no guarantee that this (extraction) is possible. Note that we can do without this derivation since we can set each key separately.
Below you will find the different modes for steem + hardware wallet(HW).
Mode Low Security
The HW is plugged once
All the keys are generated on the HW but are extracted to be used as we do today. The HW serves mainly as backup for your password.
Mode Mid Security
The HW is plugged for Active permissions
All he keys are generated on the HW but only the Posting key is extracted. If the user is a witness, the witness key would obviously need to be extracted to be use on the witness node. Note that this would be annoying for the price feed.
The Memo key is mainly used with the Active key, so no need to be extracted.
When Active permissions are required, the HW has to be unlocked. This makes stealing the user funds significantly harder than today.
Mode High Security
The HW is always plugged.
All the keys are generated on the HW and can not be extracted(except maybe the witness key). All actions like voting require the HW. This is a secure but cumbersome mode and most likely not for everyone.
GitHub Account
https://github.com/cryptohazard
Feel free to add comments/suggestions/questions/...