Content pfp
Content
@
0 reply
0 recast
2 reactions

Greg pfp
Greg
@greg
What are the security differences between storing a seed phrase in the following ways: - Locked note in iCloud - Password-protected in Keychain like how Rainbow does it - largeBlob with a passkey in iOS17+ I think I understand the UX implications of each, but curious about the technical side
10 replies
5 recasts
19 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
My general POV is that the security of all three is reasonably good, unless you're storing a life-changing amount of money in the wallet, in which case I would do none of these. The UX diffs between them are huge - largeBlobs wins by a big margin.
1 reply
0 recast
4 reactions

Dan Romero pfp
Dan Romero
@dwr.eth
cc @cassie 1/ Keychain is a more secure part of the operating system on iOS and macOS vs. Notes is an app, likely more basic password security (likely not encrypted) Password-protected back up is likely decent encryption, but if you forget the password you're screwed.
2 replies
1 recast
3 reactions

Joe Blau 🎩 pfp
Joe Blau 🎩
@joeblau
- DO NOT USE NOTES. They don't enforce any secure data practices since they are just stored on disk (See Disk risks on right) - KeyChain is the best option right now - A PassKey is just replaces your password — It would be something that you could use to unlock your KeyChain (Wallet in crypto)
1 reply
0 recast
1 reaction

Joe Blau 🎩 pfp
Joe Blau 🎩
@joeblau
We have a slide on this in our pitch deck… (except for the locked note). Apple gave a talk on iCloud security in 2016 at blackhat. https://youtu.be/BLGFriOKz6U?feature=shared
0 reply
0 recast
0 reaction

Agost Biro pfp
Agost Biro
@agostbiro
What’s not often discussed with largeBlob is that it gets exposed to the JS context of the requesting page, so malicious JS dependencies can steal the key material stored in largeBlob. This can be ok depending on the context, but it’s much weaker than Keychain storage imho.
0 reply
0 recast
0 reaction

Dan Romero pfp
Dan Romero
@dwr.eth
Related https://warpcast.com/dwr.eth/0xef6d810c
0 reply
0 recast
0 reaction

Sam (crazy candle person) ✦  pfp
Sam (crazy candle person) ✦
@samantha
@winstonlaoh ??
1 reply
0 recast
0 reaction

Zach pfp
Zach
@zachterrell
Locked note master race
0 reply
0 recast
0 reaction

Harpalsinh Jadeja pfp
Harpalsinh Jadeja
@harpaljadeja
Then there is Secure Enclave…
1 reply
0 recast
0 reaction

Lemma pfp
Lemma
@lemma
largeBlob is interesting, I didn't realize that was part of the webauthn spec. Pretty positive implications for e2ee products IMO
1 reply
0 recast
1 reaction