Content pfp
Content
@
https://opensea.io/collection/dev-21
0 reply
0 recast
2 reactions

Greg pfp
Greg
@greg
What are the security differences between storing a seed phrase in the following ways: - Locked note in iCloud - Password-protected in Keychain like how Rainbow does it - largeBlob with a passkey in iOS17+ I think I understand the UX implications of each, but curious about the technical side
8 replies
5 recasts
14 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
My general POV is that the security of all three is reasonably good, unless you're storing a life-changing amount of money in the wallet, in which case I would do none of these. The UX diffs between them are huge - largeBlobs wins by a big margin.
1 reply
0 recast
4 reactions

Dan Romero pfp
Dan Romero
@dwr
cc @cassie 1/ Keychain is a more secure part of the operating system on iOS and macOS vs. Notes is an app, likely more basic password security (likely not encrypted) Password-protected back up is likely decent encryption, but if you forget the password you're screwed.
2 replies
1 recast
3 reactions

Joe Blau 🎩 pfp
Joe Blau 🎩
@joeblau
- DO NOT USE NOTES. They don't enforce any secure data practices since they are just stored on disk (See Disk risks on right) - KeyChain is the best option right now - A PassKey is just replaces your password — It would be something that you could use to unlock your KeyChain (Wallet in crypto)
1 reply
0 recast
1 reaction

Joe Blau 🎩 pfp
Joe Blau 🎩
@joeblau
We have a slide on this in our pitch deck… (except for the locked note). Apple gave a talk on iCloud security in 2016 at blackhat. https://youtu.be/BLGFriOKz6U?feature=shared
0 reply
0 recast
0 reaction

Harpalsinh Jadeja pfp
Harpalsinh Jadeja
@harpaljadeja
Then there is Secure Enclave…
1 reply
0 recast
0 reaction

Dan Romero pfp
Dan Romero
@dwr
Related https://warpcast.com/dwr.eth/0xef6d810c
0 reply
0 recast
0 reaction

Zach pfp
Zach
@zachterrell.eth
Locked note master race
0 reply
0 recast
0 reaction

Lemma pfp
Lemma
@lemma
largeBlob is interesting, I didn't realize that was part of the webauthn spec. Pretty positive implications for e2ee products IMO
1 reply
0 recast
1 reaction