Bitcoin Forum
May 03, 2024, 11:09:56 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Feat Request] - Solution for Lost Wallet Passphrase  (Read 1098 times)
AliceWonder (OP)
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
July 11, 2013, 08:25:29 AM
 #1

Since I joined this forum, I've seen more than one thread where someone forgot their passphrase to their encrypted wallet and wanted help cracking it.

What if as an option, a user could enter the address of, say, a paper wallet beforehand.

Then whenever the user enters the passphrase to decrypt the wallet, a transaction is created and signed but not sent - that would send all inputs to that address. This transaction is then stored in the data directory.

In the event that the user can not recall their passphrase, that transaction could then be sent so at least the user has not lost all their coins.

Obviously it would not be able to include inputs created after the last time the user decrypted the wallet.dat but it could include all inputs that could be spent the last time wallet.dat was decrypted.

It might soften the financial blow to some people when they forget their passphrase.

Speaking as someone who sometimes has memory problems due to head injuries, I think it would be a welcome addition, and might even convince me to not keep my passphrase on a piece of paper in my desk drawer (There are days I can not even remember my own phone number).

QuarkCoin - what I believe bitcoin was intended to be. On reddit: http://www.reddit.com/r/QuarkCoin/
"Governments are good at cutting off the heads of a centrally controlled networks like Napster, but pure P2P networks like Gnutella and Tor seem to be holding their own." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714777796
Hero Member
*
Offline Offline

Posts: 1714777796

View Profile Personal Message (Offline)

Ignore
1714777796
Reply with quote  #2

1714777796
Report to moderator
1714777796
Hero Member
*
Offline Offline

Posts: 1714777796

View Profile Personal Message (Offline)

Ignore
1714777796
Reply with quote  #2

1714777796
Report to moderator
TierNolan
Legendary
*
Offline Offline

Activity: 1232
Merit: 1083


View Profile
July 11, 2013, 08:34:04 AM
 #2

Since I joined this forum, I've seen more than one thread where someone forgot their passphrase to their encrypted wallet and wanted help cracking it.

What if as an option, a user could enter the address of, say, a paper wallet beforehand.

This is pretty much what Armory does.  However, it doesn't need to actually generate the transaction.

You have 1 root key and all public and private keys can be generated from that.  You can then print that key to a sheet of paper and keep it somewhere safe.

If you give the software your root key, then it can scan the chain and find all coins that are yours (and send them to an address).

Quote
Then whenever the user enters the passphrase to decrypt the wallet, a transaction is created and signed but not sent - that would send all inputs to that address. This transaction is then stored in the data directory.

This would have to be one transaction per coin output.  Effectively, when a coin is received, a tx is created to send it to some other fixed address.

You still need to secure that other address though.

So, you don't get much benefit over a deterministic wallet.

1LxbG5cKXzTwZg9mjL3gaRE835uNQEteWF
AliceWonder (OP)
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
July 11, 2013, 10:03:34 AM
 #3

One of the problems I have with the alt clients, I don't know if Armory does this, but it seems that many of them use the same address for change every time.

That's a problem because if someone is able to identify any address with me, it then is possible for them to figure out what address was used as change when the input for that address was spent. And if the change address is the same every time, it's game over, they now can identify all kinds of addresses I sent money to and sent money from.

That's the primary reason I'm sticking with bitcoin-qt. It uses fresh change address each time change is needed.

QuarkCoin - what I believe bitcoin was intended to be. On reddit: http://www.reddit.com/r/QuarkCoin/
TierNolan
Legendary
*
Offline Offline

Activity: 1232
Merit: 1083


View Profile
July 11, 2013, 10:28:57 AM
 #4

One of the problems I have with the alt clients, I don't know if Armory does this, but it seems that many of them use the same address for change every time.

I don't know what Armory does, but I would be surprised if it re-uses addresses.  The whole point of the system is that you can easily generate new addresses.

If that is your only concern, then you should just ask in the Armory forum.

I think deterministic wallets are being considered for the main-client, but I don't know what the timeline is.

With Armory, the root key consists of 2 parts, the private key and the chaincode.

If someone obtains your chaincode, they can generate the public key (but not the private key) for all your transactions.

For full privacy, you need to protect both.

However, a merchant would have to put their chaincode on the customer facing server, or it wouldn't be able to generate new public keys.  However, the private root key should be kept on a different/more secure server.

1LxbG5cKXzTwZg9mjL3gaRE835uNQEteWF
jl2012
Legendary
*
Offline Offline

Activity: 1792
Merit: 1093


View Profile
July 11, 2013, 10:31:58 AM
 #5

One of the problems I have with the alt clients, I don't know if Armory does this, but it seems that many of them use the same address for change every time.

That's a problem because if someone is able to identify any address with me, it then is possible for them to figure out what address was used as change when the input for that address was spent. And if the change address is the same every time, it's game over, they now can identify all kinds of addresses I sent money to and sent money from.

That's the primary reason I'm sticking with bitcoin-qt. It uses fresh change address each time change is needed.

Armory does not reuse address by default

Donation address: 374iXxS4BuqFHsEwwxUuH3nvJ69Y7Hqur3 (Bitcoin ONLY)
LRDGENPLYrcTRssGoZrsCT1hngaH3BVkM4 (LTC)
PGP: D3CC 1772 8600 5BB8 FF67 3294 C524 2A1A B393 6517
etotheipi
Legendary
*
expert
Offline Offline

Activity: 1428
Merit: 1093


Core Armory Developer


View Profile WWW
July 11, 2013, 02:17:35 PM
 #6

Use Armory.  Print a paper backup.  Keep it in a safe place.

Armory never reuses addresses.  All change always goes to the next address in your infinite list of addresses backed up by your paper backup.  It's the "right way", as evidenced by the fact that BIP 32 is basically an extension of that that will eventually used in Bitcoin-Qt and other alt clients.

Founder and CEO of Armory Technologies, Inc.
Armory Bitcoin Wallet: Bringing cold storage to the average user!
Only use Armory software signed by the Armory Offline Signing Key (0x98832223)

Please donate to the Armory project by clicking here!    (or donate directly via 1QBDLYTDFHHZAABYSKGKPWKLSXZWCCJQBX -- yes, it's a real address!)
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4158
Merit: 8382



View Profile WWW
July 11, 2013, 03:14:43 PM
 #7

Since I joined this forum, I've seen more than one thread where someone forgot their passphrase to their encrypted wallet and wanted help cracking it.
What if as an option, a user could enter the address of, say, a paper wallet beforehand.
In that case: Just write the passphrase down.  It has the same security exposure to as your paper wallet backup, but its simpler and involves less things to get wrong.
grau
Hero Member
*****
Offline Offline

Activity: 836
Merit: 1021


bits of proof


View Profile WWW
July 11, 2013, 05:14:14 PM
 #8

Use Armory.  Print a paper backup.  Keep it in a safe place.

Armory never reuses addresses.  All change always goes to the next address in your infinite list of addresses backed up by your paper backup.  It's the "right way", as evidenced by the fact that BIP 32 is basically an extension of that that will eventually used in Bitcoin-Qt and other alt clients.
Are serialized BIP32 keys interoperable with Armory? If not yet, is it planned?
etotheipi
Legendary
*
expert
Offline Offline

Activity: 1428
Merit: 1093


Core Armory Developer


View Profile WWW
July 11, 2013, 05:23:14 PM
 #9

Use Armory.  Print a paper backup.  Keep it in a safe place.

Armory never reuses addresses.  All change always goes to the next address in your infinite list of addresses backed up by your paper backup.  It's the "right way", as evidenced by the fact that BIP 32 is basically an extension of that that will eventually used in Bitcoin-Qt and other alt clients.
Are serialized BIP32 keys interoperable with Armory? If not yet, is it planned?

I am about 70% done with the new wallet format that will accommodate all sorts of new stuff, including BIP 32.  I plan to standardize the wallet operations to BIP 32 as closely as possible, for interoperability.  But I got distracted by some the RAM issues and am working on that right now.  As soon as I'm done, I'll be upgrading the wallets.

Founder and CEO of Armory Technologies, Inc.
Armory Bitcoin Wallet: Bringing cold storage to the average user!
Only use Armory software signed by the Armory Offline Signing Key (0x98832223)

Please donate to the Armory project by clicking here!    (or donate directly via 1QBDLYTDFHHZAABYSKGKPWKLSXZWCCJQBX -- yes, it's a real address!)
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!