Bitcoin Forum
September 27, 2026, 09:28:03 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 [7]  All
  Print  
Author Topic: 🔓 Lock.com - Software isolation will replace the hardware wallet [PREVIEW]  (Read 2224 times)
snowpega
Hero Member
*****
Offline

Activity: 1064
Merit: 510


AntiSwap.io - NO AML/KYC EXCHANGER MONITORING


View Profile WWW
September 11, 2026, 01:08:58 PM
 #121

Yes, I did, and if you are using Gmail, then check the Promotions tab. I saw that mail there.

Oh, my bad. Checking on it later, I found my mail in the spam folder; it was not in the Promotions section.

I also left my email in the field for early access testers on their website, but I haven't received any email yet. Although it seems to me that it would be logical to receive an answer: "your application will be reviewed as soon as a new stage of wallet testing begins. It is possible that you will participate." I was calm, knowing that my application had worked. Well, it's okay, we'll wait until we get letters about approved testing applications in the third quarter of this year. Who knows, maybe we'll be the ones who stand at the threshold of something great. I personally love being a beta tester. This feeling of being a pioneer is always exciting and wonderful.

Are you still looking for your email? Check your spam box. Maybe, just like me, your missed email is in the spam box section.



Other than this is feels better to see the team respond to all those queries that members have been asking for a long time.

Dareo
Full Member
***
Offline

Activity: 406
Merit: 186



View Profile
September 11, 2026, 04:38:27 PM
 #122

We know that the recent Trezor data breach exposed the names and home addresses of 81,000 users, which could pose a serious risk of physical attacks. In this regard, Lock model is great because you can use your old device as a hardware wallet. And since the code will be open, there is no fear of physical address leaks.

BIP-39 also has a much more mature ecosystem of independent recovery tools. As UQS documentation and tooling are published, independent recovery and interoperability will need to be part of its review.
Since you mentioned that UQS needs to develop an independent recovery ecosystem. This means we don't have to depend on any third-party tools, we can recover it ourselves.

safar1980
Legendary
*
Offline

Activity: 2590
Merit: 2232


#kycfree 🗽


View Profile
September 11, 2026, 08:47:55 PM
 #123

It turns out that not all modern hacks and thefts from hardware wallets are related to AI these days. You may have heard that yesterday news came out about the largest lawsuit, worth 500 million, filed by victims of a long‑ago Ledger hack. And now the representatives of this hardware wallet will need to defend their reputation, even though there are many victims and huge sums were stolen from each of them. And all of this is due to a database hack in 2020. For the Lock team, this is another opportunity to remind the community about their new technological solution in comparison with “hardware” methods.
The legal prospects for such cases are very slim, but perhaps the company will agree to pay compensation to prevent the case from dragging on for years and tarnishing Ledger's reputation. In the US, 95% of such cases typically result in compensation.


And in this project it would be interesting to see a working solution.

▄███████████████████████▄
██████████▀███▄██████████
████████▀████▀▀██████████
█████████████████▀███████
███████▀▄████▄▄██████████
██████████▄███▀██████████
████████▐███████▌████████
██████████▄███▀██████████
██████████▀▀████▀▄███████
███████▄█████████████████
██████████▄▄████▄████████
██████████▀███▄██████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
░▀▀██▀▀
internetional
Legendary
*
Offline

Activity: 2310
Merit: 3598



View Profile
September 13, 2026, 08:45:51 PM
Merited by nc50lc (1)
 #124

I've carefully read the entire discussion. As I understand it, Lock's architecture is designed to support Lightning without exposing the private key to the network-facing component. What I still don't understand from the discussion is how Lightning state will be stored and updated securely. madebylock, could you explain this in more detail?

░░░░▄▄████████████▄
░▄████████████████▀
▄████████████████▀▄█▄
▄███████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀░▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀░▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄░▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀░
▀████████████▀▀░░░░
 
 CCECASH 
nc50lc
Legendary
*
Online Online

Activity: 3276
Merit: 9192


Self-proclaimed Genius


View Profile
September 14, 2026, 05:01:13 AM
 #125

I've carefully read the entire discussion. As I understand it, Lock's architecture is designed to support Lightning without exposing the private key to the network-facing component. What I still don't understand from the discussion is how Lightning state will be stored and updated securely. madebylock, could you explain this in more detail?
I'm interested on this as well.
Good question, it's a very small detail in the updated answers but a big question if it's feasible.

Unless it'll be handled by a third-party or custodial setup,
The common way to achieve this in a self-custodial way is to either require the treasury every time the user needs to use their channel(s),
Or to derive an extended private key from the master private key at a specific derivation path that'll be used for lightning network.
But the latter defeats the purpose of an air-gap setup (at least on the LN side) even though the master prvKey is still safely stored there.

Ashawowo(OS)
Full Member
***
Offline

Activity: 196
Merit: 159



View Profile
September 15, 2026, 09:14:34 AM
 #126


THE UNIVERSAL QUANTUM SEED

UQS addresses a different part of the long-term security model: generation, transcription, and recovery of the wallet's root seed.

The 36-word UQS format encodes 272 bits of entropy and includes a 16-bit checksum.
It is more secure than the current 12-word BIP system; however the 36-word UQS visual icon format implies that the seed backup must be stored digitally. Is there any way to write it down on a piece of paper, or must it be kept in digital form?
I really don't think we'll be able to write visual representation down by ourselves, but I know that since there's an option of using it as a cold storage setup, then it means there would be a provision to back it up, a quick guess should be exporting it in QR code format, then print and store offline. so when you want to reimport,  it's scanned by the wallet and the keys retrieved to set it up. It would be good if madebylock clears the air on this as well.

madebylock (OP)
Copper Member
Newbie
*
Offline

Activity: 6
Merit: 76


View Profile WWW
September 25, 2026, 01:46:07 PM
Last edit: September 25, 2026, 02:24:21 PM by Mitchell
 #127


THE UNIVERSAL QUANTUM SEED

UQS addresses a different part of the long-term security model: generation, transcription, and recovery of the wallet's root seed.

The 36-word UQS format encodes 272 bits of entropy and includes a 16-bit checksum.
It is more secure than the current 12-word BIP system; however the 36-word UQS visual icon format implies that the seed backup must be stored digitally. Is there any way to write it down on a piece of paper, or must it be kept in digital form?
I really don't think we'll be able to write visual representation down by ourselves, but I know that since there's an option of using it as a cold storage setup, then it means there would be a provision to back it up, a quick guess should be exporting it in QR code format, then print and store offline. so when you want to reimport,  it's scanned by the wallet and the keys retrieved to set it up. It would be good if madebylock clears the air on this as well.

Yep, you can absolutely back UQS up on paper. The visual icons are not a requirement for digital storage, and you do not need to keep a screenshot or QR code.

The intended recovery model is still the familiar one: record the seed phrase in order, store it offline, and re-enter it later if you need to recover. For the 36-word UQS format that means writing down all 36 words in the correct order, including the final two checksum words.

The icons are an additional recognition layer. Each of the 256 words has a corresponding icon, and the same icon is mapped across 42 language tables. So the visual representation is there to make recognition and cross-language recovery easier, not to force a digital backup.

If you prefer something printed rather than handwritten, Treasury also supports explicit seed export/print flows. But that is optional, and we would treat any generated PDF/file/print job as sensitive secret material.

And if you use the optional seed passphrase, that needs to be preserved as part of your recovery plan too.

So the short version is: paper backup is fully supported; QR is not required.



Quote from: nc50lc link=topic=5587463.msg67122600#msg67122600
It's not something that will make me switch my existing setup but its other features are worth checking out.

That is a reasonable position. We are not expecting someone with a working offline Electrum setup to replace it simply because another wallet has more features.

“Modular” captures part of the design, but the important distinction is separation of authority rather than just reducing the size of each binary.

Treasury owns the seed-dependent operations. Node handles public-chain connectivity. Wallet handles the everyday presentation and orchestration. Requests cross explicit authenticated boundaries rather than those roles sharing unrestricted access to the same private state.

That is not a claim that Treasury contains nothing except a tiny signing function. It has supporting services and domain handlers, and those still need review. Equally, the presence of additional code in an Electrum binary is not, by itself, evidence of a security weakness.

The comparison we think matters is what each running component can access, which inputs it accepts, and what a compromise would authorise.

For your existing Bitcoin setup, the practical benefit may be limited. The broader use case is making isolated signing available across other supported assets and workflows without putting the seed into the everyday online interface.



Quote from: ZAINmalik75 link=topic=5587463.msg67125470#msg67125470
I understand the architecture, but I hope the final product is simple enough that a non-technical person can actually use it

That is the goal. Someone should not need to understand key encapsulation, process isolation or a Lightning state machine to use the wallet.

The technical explanation is for people who want to examine the security model. The everyday experience should make a much smaller set of things clear: which device holds the keys, what you are authorising, whether the signing device is available, and how to back up and recover.

There is a real trade-off we should make visible, though. The high-security setup uses a dedicated Treasury device, so it involves more setup than installing a conventional wallet on one phone. We will make that process understandable rather than hide the difference.

For us, useful usability feedback is whether someone can set it up, pair their devices, understand a transaction and complete a recovery without having to read the whitepaper.

That has to be demonstrated through the product. A clear architecture diagram is not the same thing as a clear user experience.

Which part feels least intuitive to you at the moment: the separate signing device, pairing, or the backup process?
Yamane_Keto
Hero Member
*****
Offline

Activity: 994
Merit: 616



View Profile WWW
September 25, 2026, 03:22:03 PM
 #128

So the short version is: paper backup is fully supported; QR is not required.
What would happen if Lock.com went offline or the wallet code stopped working? There are no wallets that support a 36-word phrase. are there any open-source tools capable of extracting the private key?

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
nc50lc
Legendary
*
Online Online

Activity: 3276
Merit: 9192


Self-proclaimed Genius


View Profile
September 26, 2026, 05:14:48 AM
 #129

-snip-
Thanks,
I'm not expecting an answer to my reply on your previous post but more disclosed information is good.

But how about the question raised by internetional above? (the one I've sent 1 merit)

Pages: « 1 2 3 4 5 6 [7]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!