Repository navigation
Releases: hobby-eng/mhfe
Releases · hobby-eng/mhfe
Release list
MHFE v0.5.0
MHFE 0.5.0 implements suites MHFE-BIP39-256-EXPERIMENTAL-3 and MHFE-BIP39-LP-EXPERIMENTAL-4 and
the optional profiles MHFE-REPAIR-1, MHFE-PASSWORD-CHECK-1 and MHFE-WALLET-CHECK-SEED-1, as defined
by specification v0.5.0 (DOI
10.5281/zenodo.23179003). Suite 3 is unchanged:
containers made with version 0.4.0 stay readable.
Changes
- Cosmos and Injective wallet references reject redundant Bech32 data groups, including strings
with a valid checksum whose extra bits would otherwise be discarded. - Containers of the same length (suite 4,
MHFE-BIP39-LP-EXPERIMENTAL-4). For a phrase of 12,
15, 18 or 21 words,mhfe encryptnow asks how long the container should be: 24 words, the
recommended default, or the same length as the phrase. The question links to the README's
section on the choice,?compares both, and--same-lengthchooses the same length without
asking. Such a container keeps the backup's length but has no
built-in check: a wrong password gives another valid phrase, the container shows the phrase's
length, and a miscopied word passes its shorter checksum more often.mhfe decryptand
mhfe checkrecognise it by its word count; a recovered phrase from it is always shown as not
verified, andmhfe checkcompares it with an address or the fingerprint. The browser package
takessameLength: trueand reportssuiteId; its API version is 7. - A chosen original length now admits only a 24-word container or a same-length container of exactly
that length, and a selected suite only its own containers; everything else is refused before any
Argon2 work, as the specification's recovery table requires. New error codes:
SAME_LENGTH_NEEDS_SHORT_PHRASE,LENGTH_CHOICE_NOT_APPLICABLEandNO_BUILT_IN_CHECK. - The format of a container (its suite identifier) is shown after an encryption and when a container
is read, instead of at the start. - Questions are answered from lists, as in the menu: the arrow keys and Enter, or an answer's
number at once; Escape cancels (q too, where the keyboard has it). This replaces the typed
y/nanswers ofmhfe encryptand the typed choice ofmhfe check. Laid out as in MnemoCode,
each question stands apart with a short explanation, and once answered it gives way to one line
of a summary. Scripts (--stdin) answer as before. mhfe rekeyputs the same seed phrase into a new container under a new password or new
settings. It encrypts again only once the recovery is confirmed: by the built-in check at the
length the owner states, or, for a 24-word phrase or a same-length container, by an address or
the fingerprint of the wallet or by the owner, who sees the phrase on a private screen and
compares it with their backup. The library offers this as
Mhfe::recover_confirmed, with the new error codesREFERENCE_REQUIREDand
REFERENCE_MISMATCH. It warns every time that wallets of other passwords on the old container
change and asks every user to confirm that their funds are moved or backed up another way, and
it says before and after that the old container stays valid until it is destroyed. The start menu
offers it.mhfe newmakes a new 24-word wallet and its container. With a BIP39 passphrase for it, the owner
chooses no check or a wallet check with the passphrase (a draft, 16 bits): the phrase is drawn so
that a tagged hash of its BIP39 seed starts with 16 zero bits, andmhfe checkwith the
passphrase recognises the right password. The library haswallet_checkand
Reference::WalletCheck, which never confirms a rekey; the check may also be tested without a
passphrase, andmhfe decryptreports in one line when a recovered 24-word phrase passes it
without one, and says nothing otherwise.derive_wallettakes the main wallet's passphrase, so
that no hidden wallet passes the check, with it or without a passphrase.mhfe walletsopens hidden wallets: every other password gives its own 24-word wallet on a
24-word container, shown on one private screen that the main screen keeps no trace of, not even
how many wallets were opened, and recorded nowhere; the README advises running
mhfe self-testbefore funding one.
A password whose wallet passes a short phrase's built-in check is refused. The library offers
Mhfe::derive_wallet, with the error codeHIDDEN_WALLET_PASSES_CHECK.- A phrase that was not asked for as a result is shown only on a private screen:
mhfe newand
mhfe walletsrefuse to start, andmhfe rekeydoes not offer the owner's comparison, when
standard output goes to a file, a pipe, another terminal than standard error's or a terminal
without a private screen. - Every seed phrase and container shown at a terminal has its master key fingerprint on the line
below, for comparing with a wallet app: with the new wallet's BIP39 passphrase inmhfe new, and
without one inmhfe decrypt,rekeyandwallets, which do not know it. Under a container
(encrypt,new,rekey,repair) it is the fingerprint of the container's own words, not of
the original wallet. The summary and the output for scripts do not show it. - Repair words for a plate (MHFE-REPAIR-1, an optional profile of the specification): 2, 4, 6 or
8 extra words on a card kept apart from the plate, a Reed–Solomon code over its words, repair
unreadable or wrongly copied words without the password.mhfe encrypt,newandrekeyoffer
them under the new container,mhfe repair-wordsmakes them for a container you have and
mhfe repairrepairs a plate with them; the start menu has one entry for both. The library has
repair::repair_wordsandrepair::repair, with the error codesINVALID_REPAIR_WORDSand
REPAIR_NOT_POSSIBLE. mhfe self-testchecks the program on this computer against two published vectors at full cost,
an encryption of suite 3 and a recovery of suite 4, in about two minutes. The start menu offers
it.mhfe password --chars Nmakes N random characters (16 by default, about 93.3 bits) from 57
letters and digits without look-alikes, instead of dice words.mhfe password --check-wordmakes five dice words and a sixth computed from them, the check
word of the optional profile MHFE-PASSWORD-CHECK-1, still about 64.6 bits. When a password of
six list words is typed, a forgotten word typed as?or a misspelt one is restored, a wrong
word gets its six possible repairs, and extra spaces or capitals are offered corrected. Each is
used only when chosen and before any Argon2 work; the password as typed is always an answer,
and the summary says how the check word came out.mhfe encryptestimates the strength of a typed password and warns below about 50 bits, instead
of warning whenever it is not four dice words. The estimate needs no dependency: it reads the
password as words of the EFF and BIP39 lists, common passwords, years, repeats, runs and keyboard
rows, with letter substitutions, and the README states what it can overrate.- The start menu's password generator first asks for five dice words, five words and a check word
or sixteen random characters, repeats on Enter and returns to the menu on Escape. Each password
replaces the previous one on the private screen, which is cleared when leaving. - Secrets are typed on a private screen, the terminal's alternate screen, which shows them as they
are typed and is cleared as soon as they are accepted, with no question to confirm them: a
mistyped word is refused by the word list or the checksum. This replaces the hidden prompts and
the questions whether to show the words or the password. A container typed for a recovery or a
check is read the same way. The new container and a recovered seed phrase are shown on a private
screen too, which Enter or Escape clears once they are written down. Each answered step gives
way to one line of a summary on the main screen, and warnings stand apart, so that the next
question is always at the bottom. - At a terminal, every step of a command has a clean screen of its own, with nothing of the start
menu or the earlier steps above it, and when the command ends the main screen gets the summary.
Each password prompt says which password it asks for, and "NOT" in capitals marks where a
container password and a BIP39 passphrase differ. - Screens keep to short lines while a command runs. Explanations moved to the README, whose
commands now have sections of their own, and a grey "More:" line links to the section that
explains a question, a warning or a result. After an encryption, two lines say what to keep and
what to do next. - Arrow-key menus redraw correctly after the terminal width changes: the start menu repaints, and
an answer list keeps the rows it was drawn in on the alternate screen, which terminals do not
rewrap, while leaving the phrase above a confirmation visible. - The program and its documents say "seed phrase" where they said "recovery phrase", so that it
is not confused with recovering one:mhfe decryptis now "Recover a seed phrase". - Secrets stay out of core dumps and swap on Linux and macOS: the tool forbids core dumps and, on
Linux, other programs of the same user from reading its memory; it keeps the password, the
phrases and a BIP39 passphrase in locked memory, and on Linux marks Argon2's work area to be left
out of a dump. None of this applies on Windows or in the browser. A typed line
stays locked until it is wiped, and a page that holds several secrets stays locked until the last
of them is wiped. On Linux it warns before any secret is typed when swap is not encrypted. - On Linux
encrypt,decrypt,check,rekey,new,walletsand
passwordapply kernel restrictions: seccomp refuses socket creation, and io_uring, through which
the kernel could create one uns...
MHFE v0.4.0
Full Changelog: v0.3.0...v0.4.0
MHFE: Memory-Hard Feistel Encryption for BIP39 Mnemonics v0.3.0
What's Changed
- Bump actions/checkout from 4.4.0 to 7.0.1 by @dependabot[bot] in #1
- Bump bip39 from 2.2.2 to 3.0.0 by @dependabot[bot] in #2
- Bump serde_json from 1.0.149 to 1.0.151 by @dependabot[bot] in #4
- Bump zeroize from 1.8.2 to 1.9.0 by @dependabot[bot] in #5
New Contributors
- @dependabot[bot] made their first contribution in #1
Full Changelog: https://github.com/hobby-eng/mhfe/commits/v0.3.0