Adam Bliss
2018-11-18 17:56:22 UTC
I'm looking over the docs at
https://github.com/urbit/fora-posts/blob/master/proposals/posts/~2018.11.8..19.31.59..ba77~.md
but they are a bit thin and I'm a little confused.
It seems like the "ticket" is just a random number, downloaded from Tlon,
which determines the "master seed". Why not just give us the "master seed"?
It also seems like the ticket has no verifiable relationship with any of
the outputs (which all mention an "optional passphrase"). (Or is that
wrong? Can the outputs be verified by tlon to have come from the original
ticket? If so what is the point of the optional passphrase?)
So then what is the point of the whole process? If Tlon wants to transfer
ownership to our wallets, shouldn't we each start the process with an
independent pool of entropy, and send Tlon our public keys? Or if Tlon
wants to retain ownership of all the entropy (along with the ability to
reissue everyone's wallets themselves), shouldn't the optional passphrases
be removed from the wallet-generation?
Also why did Urbit fork off "Argon2u"? What advantage does it offer over
plain Argon2id?
Cheers,
--Adam
https://github.com/urbit/fora-posts/blob/master/proposals/posts/~2018.11.8..19.31.59..ba77~.md
but they are a bit thin and I'm a little confused.
It seems like the "ticket" is just a random number, downloaded from Tlon,
which determines the "master seed". Why not just give us the "master seed"?
It also seems like the ticket has no verifiable relationship with any of
the outputs (which all mention an "optional passphrase"). (Or is that
wrong? Can the outputs be verified by tlon to have come from the original
ticket? If so what is the point of the optional passphrase?)
So then what is the point of the whole process? If Tlon wants to transfer
ownership to our wallets, shouldn't we each start the process with an
independent pool of entropy, and send Tlon our public keys? Or if Tlon
wants to retain ownership of all the entropy (along with the ability to
reissue everyone's wallets themselves), shouldn't the optional passphrases
be removed from the wallet-generation?
Also why did Urbit fork off "Argon2u"? What advantage does it offer over
plain Argon2id?
Cheers,
--Adam
--
You received this message because you are subscribed to the Google Groups "urbit" group.
To unsubscribe from this group and stop receiving emails from it, send an email to urbit-dev+***@googlegroups.com.
To post to this group, send email to urbit-***@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
You received this message because you are subscribed to the Google Groups "urbit" group.
To unsubscribe from this group and stop receiving emails from it, send an email to urbit-dev+***@googlegroups.com.
To post to this group, send email to urbit-***@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.