13 ms·
Hedgehog Ethereum wallet: Build DApps like apps, without centralized keys
- tomhschmidt 7y agoThis is so badly needed in the Ethereum space. Metamask is a massive drag and a known onboarding blocker -- Hedgehog seems like a huge leap forward. Congrats team!
- michaelsbradley 7y agoCheck out Dapper and Fortmatic as well.
- aakilfernandes 7y agoThis could occupy a useful space, but it is by no means a Metamask replacement (which they explain why).
- invalidmonk 7y agoExcited to see what people build with this
- emilyhou 7y agoThis is awesome! Looks so much more streamlined and easier to use. Excited to see it used widely.
- roneil 7y agoHey all - I'm Roneil, one of the cofounders of Audius. We built Hedgehog to solve a specific pain point we faced - how can we get non crypto-native / non-technical users to sign up for a decentralized app? Current onboarding flows using Metamask and other alternatives were too cumbersome, time-consuming, and restrictive for our needs. We needed a way to generate a wallet on behalf of a user without them even knowing crypto was operating behind the scenes. Hedgehog lives in your front end Javascript code. A user enters a username (or email) and password, which is used to secure a set of encrypted auth artifacts that are generated client-side and stored in the browser’s localStorage / on your (the application developer's) server. In this way, the encrypted auth artifacts can be retrieved and consumed on secondary devices without centralizing custody and control of the private key. If the centralized server hosting the keys goes down, users can continue to access their wallet on the devices they already have. If the centralized server is compromised or operated by bad actors, the resources required to decrypt a stored auth artifact would be immense. However - this is why we recommend using Hedgehog only in low-to-no financial value use cases. This approach is not without tradeoffs - but for the right use-cases we believe this will provide a needed alternative. Happy to answer any questions you all have!
- atomical 7y agoIs there any way to recover a login and password if the user forgets it?
- michaelsbradley 7y agoNo. See: https://audiusproject.github.io/hedgehog-docs/#important-lost-passwords https://audiusproject.github.io/hedgehog-docs/#important-los...
- roneil 7y agoThanks for checking out Hedgehog! There is not - this is the biggest deficiency of Hedgehog today. Without centralized custody of keys, it's not possible to have someone prove their ownership of a given key to a centralized party in order to unlock it. The key is encrypted, so the application provider nor anyone else can decrypt it without the user's username/password combination. This tradeoff is both a good thing and a bad thing in our view. That said, there is a mechanism for changing your password if you are already signed in. We are considering some mechanisms for fallbacks, eg using a threshold cryptosystem with multiple private keys and a 1 or 2 of n requirement, such that if a user forgets the way to generate one of the n keys they may still remember a way to generate the other(s). If you're curious, more on these schemes here: https://en.wikipedia.org/wiki/Threshold_cryptosystem https://en.wikipedia.org/wiki/Threshold_cryptosystem We feel these tradeoffs make sense to enable more mainstream adoption of cryptocurrencies, but they are tradeoffs; for certain types of applications the cost of losing control of an account is too high for this approach to make sense.
- michaelsbradley 7y agoHas there been any thought as to how the REST API + database side of this could be replaced with ipfs/swarm? I'm not sure how it would work, and there would likely be additional trade-offs, but it would be nice if the "D" in DApps could be retained in full.
- roneil 7y agoThere has! This could be a great approach - eg. a network of folks committed to supporting users in this manner could operate IPFS nodes that re-pin the encrypted keys. We are also thinking about offline ways to share the key such that the centralized side is not required - eg. a QR code displayed on one device and scanned by another to propagate the wallet. This creates a problem if a user loses all of their devices though.
- alexgpark 7y agoLooks compelling, been waiting for something like this to come along. Built a couple dapps with Metamask and the popups and mnemonic phrases and browser extension installation were a serious UX issue that had no real workaround and seemingly no timeline for improvement. AFAIK, development seems to have slowed or stopped entirely on Metamask? Will try working with this and share any feedback. Nice work guys, thanks for moving the space forward
- throwayEngineer 7y agoAny Ethereum developers have a plan once ETH gets log jammed again? Apps will be slow to respond and take minutes or hours between updates. Is this accepted as you wait for a new solution to the byzantine generals problem?
- atomical 7y agoSidechains like Loom network are making progress, but Ethereum 2.0 is a ways off.
- ejanus 7y agoCould you explain you statement with facts ?
- atomical 7y agoLoom has better scalability. Most transactions can happen on a sidechain. https://medium.com/loom-network/everything-you-need-to-know-about-loom-network-all-in-one-place-updated-regularly-64742bd839fe https://medium.com/loom-network/everything-you-need-to-know-... Ethereum 2.0 will have sharding. That should speed up transactions but sidechains will probably always be cheaper and sometimes no fee.
- roneil 7y agoThe existing issues with ETH are why we currently use POA network for the Audius private beta. POA network has its own set of issues, but the 1) fast transaction confirmation time, 2) low fees, and 3) lack of congestion make it a great testbed for us. FWIW, Hedgehog works with any web3-compliant API, in our case core.poa.network but could be any other one of developer's choosing eg. Infura
- asenna 7y agoThis looks brilliant, addresses a very real pain point and your landing page communicates it well with the demo. Kudos! Will give this a try on our Dapp.
- ErikAugust 7y agoCertainly a much needed application in the Ethereum space. As a blockchain game developer, I have talked ad nauseum (https://steemit.com/marketing/@steem.marketing/cache-the-game-switching-from-ethereum-to-steem https://steemit.com/marketing/@steem.marketing/cache-the-gam...) about reasons why we switched away from Ethereum for most transactions (but not all). The UX of the wallet being one difficulty for adoption. There are other even bigger reasons (in my opinion) - variable mining fees per transaction being a large one.
- trentonv 7y agolol I made an account just to add this reply. Are you familiar with EIP 1559? There are solid efforts currently ramping up research to change the fee market from an auction to a flat fee: https://ethereum-magicians.org/t/eip-1559-fee-market-change-for-eth-1-0-chain/2783 https://ethereum-magicians.org/t/eip-1559-fee-market-change-...
- zeroxfe 7y agoI guess you can't change your password (while keeping the same private key), can you?
- roneil 7y agoYou can! This would re-encrypt your locally decrypted wallet seed using the new credential and store it under the newly generated lookup key
- homakov 7y agoIf old pw is considered leaked, new seed must be generated as well. Leaked password is the main reason why users would change passwords.
- roneil 7y agoTrue - was answering the general case of password change, eg. some folks like to rotate passwords every so often in the absence of a known leak or breach. In the case of a compromised password the entire wallet should be abandoned.
- ranidu 7y agoAwesome launch!
- miguelmota 7y agoThe hedgehog library is completely unsafe considering that any third party library or browser extension loaded in the website using the SDK can loop through localStorage to read the entropy value therefore recreating the hd wallet and stealing the user's account.
- xrd 7y agoThis. This is why FinneyFor uses an iFrame to keep the private key safe in localStorage only accessible from JS running on the same domain. FinneyFor uses postMessage to communicate between the parent frame when payment is processed, so you get the benefits of creating transactions in any kind of browser, but none of the risks as the parent rightfully points out. https://finneyfor.com/ https://finneyfor.com/
- roneil 7y agoWe documented this here: https://audiusproject.github.io/hedgehog-docs/#security-considerations https://audiusproject.github.io/hedgehog-docs/#security-cons... This is why we recommend that you audit all 3rd-party Javascript in your app for accesses to localstorage, and avoid sourcing 3rd-party javascript from uncontrolled origins (the code could be switched out from under you if it is not baked into your application) The post message model is an interesting one - we looked into designing Hedgehog in that way, but decided it ultimately did not help solve this issue and created unnecessary complexity. If you include Javascript from libraries or other origins on your page, eg. Google Analytics, that Javascript could still post-message into your iframe. Perhaps we are wrong here though! Is FinneyFor open-source? Would love to see how this is implemented.
- xrd 7y agoWe don't have any other js libraries on FinneyFor so there would never be that problem. Auditing the source code of all libraries is a tall order. And, even if you don't find a bug, there still might be some that someone else could exploit with bugs in your code and the js libraries. Finney For is not open source.