Bitcoin Forum
November 11, 2024, 09:22:30 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Questions Regarding BIP32 Security  (Read 1612 times)
2_Thumbs_Up (OP)
Sr. Member
****
Offline Offline

Activity: 323
Merit: 251


View Profile
February 20, 2015, 06:32:36 PM
Last edit: February 20, 2015, 06:53:40 PM by 2_Thumbs_Up
 #1

I'm trying to wrap my head around the security implications of HD wallets. The vulnerability I'm a bit unclear on is where a private key and a master public key together can leak a master private key.

As far as I understand HD-wallets, they consist of a pair of master keys, derived "account master keys", and then a pair of keys for every single address in every account. Say my xpub master key is known, what would someone with a single private key be able to do with this? My guess is that he could get the private account key, thus getting access to all the coins in that account, but not any other accounts. Correct? Any other things I should be aware of?

Secondly, apparently there is this thing called hardened keys as well that makes this leaking impossible, which is why it is isolated to single accounts. I assume there is some sort of drawback of this, since otherwise all keys should be derived in this manner. What's the deal here?

If there is any other non-intuitive possibility of leakage of private keys that I'm unaware of, please tell me.

Thanks.
rgenito
Full Member
***
Offline Offline

Activity: 140
Merit: 101


View Profile WWW
October 18, 2016, 11:18:04 PM
 #2

Check out this article written by Vitalik Buterin, it will answer your question... basically, do not give *any* private keys to people that should not be able to spend....ever Smiley and do not give out *any* private keys when anyone in a company has a "master public key" (or extended public key...)

https://bitcoinmagazine.com/articles/deterministic-wallets-advantages-flaw-1385450276

https://geni.app - Genius – The Crypto Solution to Retirement
RealBitcoin
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1009


JAYCE DESIGNS - http://bit.ly/1tmgIwK


View Profile
October 18, 2016, 11:20:45 PM
 #3

I have just asked the same question a few hours ago, what a coincidence, check here:

https://bitcointalk.org/index.php?topic=1652854

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!