Skip to content

Releases: hobby-eng/mhfe

MHFE v0.5.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 07:59
v0.5.0
52b6b36

MHFE 0.5.0 implements suites MHFE-BIP39-256-EXPERIMENTAL-3 and MHFE-BIP39-LP-EXPERIMENTAL-4 and
the optional profiles MHFE-REPAIR-1, MHFE-PASSWORD-CHECK-1 and MHFE-WALLET-CHECK-SEED-1, as defined
by specification v0.5.0 (DOI
10.5281/zenodo.23179003). Suite 3 is unchanged:
containers made with version 0.4.0 stay readable.

Changes

  • Cosmos and Injective wallet references reject redundant Bech32 data groups, including strings
    with a valid checksum whose extra bits would otherwise be discarded.
  • Containers of the same length (suite 4, MHFE-BIP39-LP-EXPERIMENTAL-4). For a phrase of 12,
    15, 18 or 21 words, mhfe encrypt now asks how long the container should be: 24 words, the
    recommended default, or the same length as the phrase. The question links to the README's
    section on the choice, ? compares both, and --same-length chooses the same length without
    asking. Such a container keeps the backup's length but has no
    built-in check: a wrong password gives another valid phrase, the container shows the phrase's
    length, and a miscopied word passes its shorter checksum more often. mhfe decrypt and
    mhfe check recognise it by its word count; a recovered phrase from it is always shown as not
    verified, and mhfe check compares it with an address or the fingerprint. The browser package
    takes sameLength: true and reports suiteId; its API version is 7.
  • A chosen original length now admits only a 24-word container or a same-length container of exactly
    that length, and a selected suite only its own containers; everything else is refused before any
    Argon2 work, as the specification's recovery table requires. New error codes:
    SAME_LENGTH_NEEDS_SHORT_PHRASE, LENGTH_CHOICE_NOT_APPLICABLE and NO_BUILT_IN_CHECK.
  • The format of a container (its suite identifier) is shown after an encryption and when a container
    is read, instead of at the start.
  • Questions are answered from lists, as in the menu: the arrow keys and Enter, or an answer's
    number at once; Escape cancels (q too, where the keyboard has it). This replaces the typed
    y/n answers of mhfe encrypt and the typed choice of mhfe check. Laid out as in MnemoCode,
    each question stands apart with a short explanation, and once answered it gives way to one line
    of a summary. Scripts (--stdin) answer as before.
  • mhfe rekey puts the same seed phrase into a new container under a new password or new
    settings. It encrypts again only once the recovery is confirmed: by the built-in check at the
    length the owner states, or, for a 24-word phrase or a same-length container, by an address or
    the fingerprint of the wallet or by the owner, who sees the phrase on a private screen and
    compares it with their backup. The library offers this as
    Mhfe::recover_confirmed, with the new error codes REFERENCE_REQUIRED and
    REFERENCE_MISMATCH. It warns every time that wallets of other passwords on the old container
    change and asks every user to confirm that their funds are moved or backed up another way, and
    it says before and after that the old container stays valid until it is destroyed. The start menu
    offers it.
  • mhfe new makes a new 24-word wallet and its container. With a BIP39 passphrase for it, the owner
    chooses no check or a wallet check with the passphrase (a draft, 16 bits): the phrase is drawn so
    that a tagged hash of its BIP39 seed starts with 16 zero bits, and mhfe check with the
    passphrase recognises the right password. The library has wallet_check and
    Reference::WalletCheck, which never confirms a rekey; the check may also be tested without a
    passphrase, and mhfe decrypt reports in one line when a recovered 24-word phrase passes it
    without one, and says nothing otherwise. derive_wallet takes the main wallet's passphrase, so
    that no hidden wallet passes the check, with it or without a passphrase.
  • mhfe wallets opens hidden wallets: every other password gives its own 24-word wallet on a
    24-word container, shown on one private screen that the main screen keeps no trace of, not even
    how many wallets were opened, and recorded nowhere; the README advises running
    mhfe self-test before funding one.
    A password whose wallet passes a short phrase's built-in check is refused. The library offers
    Mhfe::derive_wallet, with the error code HIDDEN_WALLET_PASSES_CHECK.
  • A phrase that was not asked for as a result is shown only on a private screen: mhfe new and
    mhfe wallets refuse to start, and mhfe rekey does not offer the owner's comparison, when
    standard output goes to a file, a pipe, another terminal than standard error's or a terminal
    without a private screen.
  • Every seed phrase and container shown at a terminal has its master key fingerprint on the line
    below, for comparing with a wallet app: with the new wallet's BIP39 passphrase in mhfe new, and
    without one in mhfe decrypt, rekey and wallets, which do not know it. Under a container
    (encrypt, new, rekey, repair) it is the fingerprint of the container's own words, not of
    the original wallet. The summary and the output for scripts do not show it.
  • Repair words for a plate (MHFE-REPAIR-1, an optional profile of the specification): 2, 4, 6 or
    8 extra words on a card kept apart from the plate, a Reed–Solomon code over its words, repair
    unreadable or wrongly copied words without the password. mhfe encrypt, new and rekey offer
    them under the new container, mhfe repair-words makes them for a container you have and
    mhfe repair repairs a plate with them; the start menu has one entry for both. The library has
    repair::repair_words and repair::repair, with the error codes INVALID_REPAIR_WORDS and
    REPAIR_NOT_POSSIBLE.
  • mhfe self-test checks the program on this computer against two published vectors at full cost,
    an encryption of suite 3 and a recovery of suite 4, in about two minutes. The start menu offers
    it.
  • mhfe password --chars N makes N random characters (16 by default, about 93.3 bits) from 57
    letters and digits without look-alikes, instead of dice words.
  • mhfe password --check-word makes five dice words and a sixth computed from them, the check
    word of the optional profile MHFE-PASSWORD-CHECK-1, still about 64.6 bits. When a password of
    six list words is typed, a forgotten word typed as ? or a misspelt one is restored, a wrong
    word gets its six possible repairs, and extra spaces or capitals are offered corrected. Each is
    used only when chosen and before any Argon2 work; the password as typed is always an answer,
    and the summary says how the check word came out.
  • mhfe encrypt estimates the strength of a typed password and warns below about 50 bits, instead
    of warning whenever it is not four dice words. The estimate needs no dependency: it reads the
    password as words of the EFF and BIP39 lists, common passwords, years, repeats, runs and keyboard
    rows, with letter substitutions, and the README states what it can overrate.
  • The start menu's password generator first asks for five dice words, five words and a check word
    or sixteen random characters, repeats on Enter and returns to the menu on Escape. Each password
    replaces the previous one on the private screen, which is cleared when leaving.
  • Secrets are typed on a private screen, the terminal's alternate screen, which shows them as they
    are typed and is cleared as soon as they are accepted, with no question to confirm them: a
    mistyped word is refused by the word list or the checksum. This replaces the hidden prompts and
    the questions whether to show the words or the password. A container typed for a recovery or a
    check is read the same way. The new container and a recovered seed phrase are shown on a private
    screen too, which Enter or Escape clears once they are written down. Each answered step gives
    way to one line of a summary on the main screen, and warnings stand apart, so that the next
    question is always at the bottom.
  • At a terminal, every step of a command has a clean screen of its own, with nothing of the start
    menu or the earlier steps above it, and when the command ends the main screen gets the summary.
    Each password prompt says which password it asks for, and "NOT" in capitals marks where a
    container password and a BIP39 passphrase differ.
  • Screens keep to short lines while a command runs. Explanations moved to the README, whose
    commands now have sections of their own, and a grey "More:" line links to the section that
    explains a question, a warning or a result. After an encryption, two lines say what to keep and
    what to do next.
  • Arrow-key menus redraw correctly after the terminal width changes: the start menu repaints, and
    an answer list keeps the rows it was drawn in on the alternate screen, which terminals do not
    rewrap, while leaving the phrase above a confirmation visible.
  • The program and its documents say "seed phrase" where they said "recovery phrase", so that it
    is not confused with recovering one: mhfe decrypt is now "Recover a seed phrase".
  • Secrets stay out of core dumps and swap on Linux and macOS: the tool forbids core dumps and, on
    Linux, other programs of the same user from reading its memory; it keeps the password, the
    phrases and a BIP39 passphrase in locked memory, and on Linux marks Argon2's work area to be left
    out of a dump. None of this applies on Windows or in the browser. A typed line
    stays locked until it is wiped, and a page that holds several secrets stays locked until the last
    of them is wiped. On Linux it warns before any secret is typed when swap is not encrypted.
  • On Linux encrypt, decrypt, check, rekey, new, wallets and
    password apply kernel restrictions: seccomp refuses socket creation, and io_uring, through which
    the kernel could create one uns...
Read more

MHFE v0.4.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 17:39

Full Changelog: v0.3.0...v0.4.0

MHFE: Memory-Hard Feistel Encryption for BIP39 Mnemonics v0.3.0

Choose a tag to compare

@github-actions github-actions released this 22 Sep 19:05

What's Changed

New Contributors

Full Changelog: https://github.com/hobby-eng/mhfe/commits/v0.3.0