For a long time, I thought of the blockchain as almost synonymous with cryptocurrencies, so as I saw stuff like “Odyssey” and “lbry” appearing and being “based on the blockchain”, my first thought was that it was another crypto scam. Then, I just got reminded of it and started looking more into it, and it just seemed like regular torrenting. For example, what’s the big innovation separating Odyssey from Peertube, which is also decentralized and also uses P2P? And what part of it does the blockchain really play, that couldn’t be done with regular P2P? More generally, and looking at the futur, does the blockchain offer new possibilities that the fediverse or pre-existing protocols don’t have?

  • manitcor
    link
    fedilink
    English
    011 months ago

    thats how it works, im not sure what you are getting at?

    • @dragontamer@lemmy.world
      link
      fedilink
      English
      3
      edit-2
      11 months ago

      Oh really, wallet hardware companies are publishing the hmac and algorithm used to go from passphrase to private key?

      Care to post one?

      • manitcor
        link
        fedilink
        English
        311 months ago

        there are opensource wallets, the standard is called BIP39

        im not sure if any of the hardware providers are doing it though

        im still not sure what you are getting at, if you are suggesting I somehow trust hardware cold wallet providers, I dont, does not mean Im not stuck using the tools.

        • @dragontamer@lemmy.world
          link
          fedilink
          English
          2
          edit-2
          11 months ago

          if you are suggesting I somehow trust hardware cold wallet providers, I dont

          I’m saying there’s an obvious solution to anyone who has passed a cryptography 101 course here.

          PKI private keys are randomly generated prime numbers and/or ellipitcal curve numbers (depending on algorithm). Either way, that random number generator needs a seed, and that seed can be based off of the passphrase. BIP39 isn’t the whole solution, that’s just a way to turn long-strings of alpha-numeric characters into binary data.

          My overall point is that there’s a blatantly obvious, simple solution to the hardware wallet problem. I brought it up because its not a hard crypto-problem to solve. The fact that there’s no adequate solution in 15 years is a failure of the cryptocoin community. Not due to a failure of basic cryptography problems.


          The cryptocoin community, despite using “cryptography” is a joke. They barely know how to use cryptography even at its most elementary levels. It takes 15 years to come up with crappy, untrusted hardware wallets and they still can’t open a basic textbook to come up with a better solution that’s already written down.

          • manitcor
            link
            fedilink
            English
            311 months ago

            the issue with the hardware wallet is not a “simple math” problem but a “trust” issue. in reality you simply can’t trust any hardware you didn’t make yourself, in practical use we usually pick vendors we like and decide to trust them.

            for example. many people considered ledger trustworthy until they introduced firmware that indicates a capability to exfiltrate the keys.

            I think the problem you are speaking to was some older hardware keys (and maybe some strange off brands) that encode keys at the factory, to my knowledge no major product does anything like that and they take pains to show you are generating the key. the big back and forth there has been with hardware providers using methods that are potentially reversible or other types of vulnerabilities.

            Yes pretty much all devices will allow you to import a key you have generated by whatever means you prefer, however once you put it on the device you are signing up for the other issues that come with hardware still.

            • @dragontamer@lemmy.world
              link
              fedilink
              English
              1
              edit-2
              11 months ago

              I don’t think you recognize how easy it is to generate trust with the methodology I laid out.

              1. Buy a standard-compliant offline wallet.
              2. Buy a second, standard-compliant, offline wallet that you know uses a different codebase, as much as possible.
              3. Generate a passphrase. Use it on #1 and #2 to generate your wallet/private keys.
              4. Is it the same private key? Success. Unless the wallets have fallen prey to the same flaw (unlikely, as they were manufactured from two separate companies and running two separate code paths), you’re probably good.

              “The Standard-compliant” method is any algorithm that goes from hmac(passphrase) into seed -> generating the random numbers needed to build a wallet. (Prime numbers or whatever). As far as I can tell, this “standard method” doesn’t exist, not yet anyway.

              • manitcor
                link
                fedilink
                English
                411 months ago

                Issue has been the workflow for that, everyone wants something that works with thier phone and self-updates. Also have only seen a couple good air-gapped signers. No one likes the offline signer story except finance governance ppl so far.