01a0eeb2 - Specify social recovery of the seed - #339
Conversation
Document the guardian backup of the user-held seed. No runtime change.
Check the reconstructed npub before a share leaves the device, and draw cancellation from a pending session as well as a ready one.
|
EN: DE: DetailsPass 1 found two contradictions in Pass 2 found no defects. The operator waived the second review lane for this pull request only. That waiver is not a passed second review. No issue comments, pull-request reviews, inline comments, or review threads were open. |
EN:
This specifies how friends can hold shares of the same 128-bit seed a passkey already derives, so a lost phone can be replaced without a paper copy.
Daily login stays a passkey. Friends act only together, after a 48-hour delay, and only toward a new device.
Nothing here is implemented: no routes, no schema, and no screens.
DE:
Das beschreibt, wie Freunde Anteile desselben 128-Bit-Seeds halten, den ein Passkey schon ableitet, damit ein verlorenes Telefon ohne Papierzettel ersetzbar ist.
Der tägliche Login bleibt ein Passkey. Freunde handeln nur gemeinsam, nach 48 Stunden Wartezeit und nur in Richtung eines neuen Geräts.
Umgesetzt ist nichts: keine Routen, kein Schema und keine Oberflächen.
Details
The specification is
docs/social-recovery.md.CONCEPT.mdadds it as recovery path 3 and a decisions-log row.README.mdlinks the document.SPEC.mdlists it under out of scope for v1 and reserves no path.Friends replace the paper copy of the seed, not the phone and not the passkey. The split secret is the frozen 16-byte
mnemonic-v1entropy, packaged as one SLIP-39 group with an empty passphrase and iteration exponent 0. Reconstruction stops at those 16 bytes and then uses the existing BIP-39 and NIP-06 path. SLIP-39's own conversion into a BIP-32 seed is not used, because that would change the npub.Each share is NIP-44 encrypted to a secp256k1 key the guardian proves by scanning a nonce from the owner's device. On recovery, guardians encrypt only to an ephemeral key the new device shows. The api stores ciphertext and must never be the source of the recipient key. A local copy on the guardian's device is the copy that still works if this service disappears.
The default offer is 2 of 3, with a threshold of at least 2. Binding a new passkey waits 48 hours even when a session is already signed in, and an existing passkey can cancel immediately. After recovery the seed is stored wrapped under the new passkey (
seed-wrap-v1); the new passkey's own PRF is not a second seed. Replacing a phrase stays refused.This applies only after the account holds its own Nostr key. The custodial nsec is not split. Open Question #9 is unchanged. Wallet of Satoshi funds are not recovered, because 21.gifts does not hold them.