we do not allow standard PGP signatures on the consensus layer.
This is done for simplicity and safety.
This means that a regular call to
$ gpg --sign will not work for handshake
airdrop proofs.
As far as SSH keys go, people typically do
not sign arbitrary messages with them.
Because of this, we require a special tool
to do both the signing and merkle proof creation.
I like how they say, simplicity and safety.The right solution: Give me a random block of text, I'll sign it using my private RSA/DSA key and you can verify that I am the owner of the public key, send me the money, and everybody is happy.
Alleged simplicity: Two hours I'm trying to redeem the airdrop without giving away the private key and the passphrase (hint, it's not implemented, despite the documentation somewhat references it here: https://github.com/handshake-org/hs-airdrop#fallback-for-hsm... ).
Alleged safety: after installing dozens of NPM packages and code from whoever who, and running an algorithm that we don't know (even the developers) if it's reversible or not.
I see horrible consequences: https://github.com/handshake-org/hs-airdrop/issues/31
User has key safely inside HSM, gets the key out to get free money that A16Z is supposedly giving.
Reminds me the "Elon Musk gives Bitcoin on Twitter, just send YOUR PASSWORD"
On the practices overall:
It's unclear what the private key derivation process does and if the developers themselves truly understand it.
If the developers would understand the full security implications, they would not say it's safe to do it on an air-gapped machine.
The process could just multiply by two or base64 encode the private key, it would be near invisible since the whole code and theory is a big soup.
All that, supposedly for privacy benefits, when at the end, you have to give your real identity and ID documents to actually withdraw/exchange the coins.
The part of the code running without --base is very complex and it would be difficult to share an opinion and I'm not sure that I understand all the sorcery (for sure the crypto people behind are very very smart)
The airdrop tool takes your private key and your passphrase, does some overcomplicated (and unconventional) magic with it and asks you to post the resulting data to the public.