4 ms·
I believe you can have the airdrop tool [0] output the raw bytes that you need to sign with your private key. Still not fool proof but makes it more transparent
by agrinman 7y ago
I believe you can have the airdrop tool [0] output the raw bytes that you need to sign with your private key. Still not fool proof but makes it more transparent what you're actually doing with the key.
[0] https://github.com/handshake-org/hs-airdrop https://github.com/handshake-org/hs-airdrop
- rvnx 7y agoWell if you get that part running I'm interested because when I run the tool on an air-gapped machine without access to SSH private key, then this bare mode is not functional and keeps saying "Address is not a faucet or sponsor address". The next step on the Namebase website is that they ask you for your passport and utility bills, and since they issued the address of your wallet, they perfectly know who received the reward. (as a note I really don't see the point of the crypto-privacy protocol, if it's supposed to hide who received rewards if you need to give your passport to transfer the coins out or exchange against other currency).
- troquerre 7y agoYeah that's how the airdrop tool works and the instructions use that tool too (the first step in the instructions just shows how to install the tool).
- rvnx 7y agoCan you ask one of your developers to try using the bare mode only ? (a concrete case, only the public key and extracting the raw bytes). Several hours, flipping the code in many ways, such option doesn't seem to exist (and for sure isn't documented)
- rvnx 7y agoMhhh, your nonce discovery process cannot work without the private key. while (br.left()) { const ct = br.readBytes(br.readU16(), true); qqq++; try { out.push(key.decrypt(ct, priv)); } catch (e) { continue; } } What you do is that you bruteforce 1500 items with the private key of the user to find the nonce. So obviously, the --bare mode cannot work the way you describe.