Derive from the mnemonic's words joined by single spaces, whatever separated them #49

Closed
opened 2026-10-04 06:27:14 +02:00 by clawbot · 1 comment
Collaborator

From the whole-branch review of #28 (#28 (comment)), finding 2:

internal/mnemonic/mnemonic.go (checked) trims only the ends of the mnemonic. The same twelve words separated by two spaces, a tab, or one per line (as a --mnemonic-command may print them) pass the BIP-39 checksum, but the seed is computed over the string as given, so every derived key differs from the README vectors, with no warning. Anything encrypted to an age identity derived that way can then only be decrypted by giving the mnemonic with exactly the same spacing.

Work, on a branch cut from next, PR to next: the seed is derived from the words joined by single spaces, whatever whitespace separated them. The README section on giving the mnemonic says so in one sentence.

Definition of done

  • One-word-per-line, double-spaced and tab-separated input give the README vectors; a test covers each.
  • No README test vector changes.
  • make check passes.

Model: opus-5-5

From the whole-branch review of https://git.eeqj.de/sneak/keyfunc/pulls/28 (https://git.eeqj.de/sneak/keyfunc/pulls/28#issuecomment-120217), finding 2: `internal/mnemonic/mnemonic.go` (`checked`) trims only the ends of the mnemonic. The same twelve words separated by two spaces, a tab, or one per line (as a `--mnemonic-command` may print them) pass the BIP-39 checksum, but the seed is computed over the string as given, so every derived key differs from the README vectors, with no warning. Anything encrypted to an age identity derived that way can then only be decrypted by giving the mnemonic with exactly the same spacing. Work, on a branch cut from `next`, PR to `next`: the seed is derived from the words joined by single spaces, whatever whitespace separated them. The README section on giving the mnemonic says so in one sentence. ## Definition of done - One-word-per-line, double-spaced and tab-separated input give the README vectors; a test covers each. - No README test vector changes. - `make check` passes. Model: opus-5-5
clawbot self-assigned this 2026-10-04 06:27:14 +02:00
Author
Collaborator

Implemented in #53: the mnemonic's words are joined with single spaces before the checksum and the seed, for every source. A test checks that one-word-per-line, double-spaced and tab-separated input each give the README SSH vector, and the README section on giving the mnemonic says this in one sentence.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/keyfunc/pulls/53: the mnemonic's words are joined with single spaces before the checksum and the seed, for every source. A test checks that one-word-per-line, double-spaced and tab-separated input each give the README SSH vector, and the README section on giving the mnemonic says this in one sentence. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#49