update docs

This commit is contained in:
PROWLERx15
2025-04-13 18:49:31 +05:30
parent a3c8f390eb
commit 01a739afaa
12 changed files with 185 additions and 180 deletions
+21 -21
View File
@@ -33,7 +33,7 @@ If you have specific questions about the project, our [Telegram Group](https://t
* Stateless, air-gapped operation:
* Temporarily stores seeds in memory while the device is powered; all memory is wiped when power is removed.
* SD card removable after boot to ensure no secret data can be written to it.
* No wifi or Bluetooth hardware onboard.
* No WiFi or Bluetooth hardware onboard.
* Can only receive data via reading QR codes with its camera.
* Can only send data by displaying QR codes on its screen.
@@ -51,7 +51,7 @@ If you have specific questions about the project, our [Telegram Group](https://t
* Import any existing seed phrase via an optimized seed word entry interface.
* Partial support for Electrum Segwit seed phrases [(info)](docs/electrum.md).
* Wallet setup and transaction signing
* Wallet setup and transaction signing:
* Script types: Taproot, native segwit, nested segwit, legacy (p2pkh).
* Single sig and multisig xpub export.
* Support for user-defined custom derivation paths.
@@ -59,7 +59,7 @@ If you have specific questions about the project, our [Telegram Group](https://t
* Verify the PSBT's single sig or multisig change outputs or self-transfer outputs.
* Mainnet, testnet, and regtest.
* Additional utilities
* Additional utilities:
* [SettingsQR](https://github.com/SeedSigner/seedsigner-settings-generator) to instantly reconfigure a SeedSigner for beginners, advanced users, or tailored to your preferences.
* Scan a software wallet's receive or change address to verify that it's correct.
* Address Explorer for single sig and multisig wallets.
@@ -93,7 +93,7 @@ To build a SeedSigner, you will need:
Notes:
* You may need to solder the 40 GPIO pins (20 pins per row) to the Raspberry Pi Zero board. If you don't want to solder, most stores offer the board "with headers" already soldered on.
* The Pi Zero "W" or "2W" is often easier to find but has wifi/Bluetooth hardware. You can still use these boards and can optionally [disable the wifi/Bluetooth hardware](https://github.com/DesobedienteTecnologico/rpi_disable_wifi_and_bt_by_hardware).
* The Pi Zero "W" or "2W" is often easier to find but has WiFi/Bluetooth hardware. You can still use these boards and can optionally [disable the WiFi/Bluetooth hardware](https://github.com/DesobedienteTecnologico/rpi_disable_wifi_and_bt_by_hardware).
* Other cameras with the above sensor module should work, but may not fit in the Orange Pill enclosure.
* Choose the Waveshare screen carefully; they make a number of different boards that look very similar but ARE NOT COMPATIBLE! Make sure you purchase the model that has a resolution of 240x240 pixels.
* Raspberry Pi 1 is also compatible, but will require a [hardware modification to the Waveshare LCD Hat](./docs/legacy_hardware.md).
@@ -111,8 +111,8 @@ Instructions to build a SeedSigner OS image (using precisely the same process th
## Downloading the Software
Download the current Version (0.8.5) software image that is compatible with your Raspberry Pi Hardware. The Pi Zero 1.3 is the most common and recommended board.
| Board | Download Image Link/Name |
| --------------------- | --------------------------------- |
|**[Raspberry Pi Zero 1.3](https://www.raspberrypi.com/products/raspberry-pi-zero/)** |[`seedsigner_os.0.8.5.pi0.img`](https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner_os.0.8.5.pi0.img) |
@@ -124,9 +124,9 @@ Download the current Version (0.8.5) software image that is compatible with your
|[Raspberry Pi 4 Model B](https://www.raspberrypi.com/products/raspberry-pi-4-model-b/) |[`seedsigner_os.0.8.5.pi4.img`](https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner_os.0.8.5.pi4.img) |
|[Raspberry Pi 400](https://www.raspberrypi.com/products/raspberry-pi-400-unit/) |[`seedsigner_os.0.8.5.pi4.img`](https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner_os.0.8.5.pi4.img) |
Note: If you have physically removed the WiFi component from your board, you will still use the image file of the original(un-modified) hardware. (Our files are compiled/based on the *processor* architecture). Although it is better to spend a few minutes upfront to determine which specific Pi hardware/model you have, if you are still unsure which hardware you have, you can try using the pi0.img file. Making an incorrect choice here will not ruin your board, because this is software, not firmware.
Note: If you have physically removed the WiFi component from your board, you will still use the image file of the original (un-modified) hardware. (Our files are compiled/based on the *processor* architecture). Although it is better to spend a few minutes upfront to determine which specific Pi hardware/model you have, if you are still unsure which hardware you have, you can try using the pi0.img file. Making an incorrect choice here will not ruin your board, because this is software, not firmware.
**also download** these 2 signature verification files to the same folder
**Also download** these 2 signature verification files to the same folder:
[The Plaintext manifest file](https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner.0.8.5.sha256.txt)
[The Signature of the manifest file](https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner.0.8.5.sha256.txt.sig)
@@ -147,7 +147,7 @@ We assume you are running the commands from a computer where both [GPG](https://
### Step 1. Verify that the signature (.sig) file is genuine:
Run GPG's *fetch-keys* command to import the SeedSigner projects public key from the popular online keyserver called *Keybase.io*, into your computers *keychain*.
Run GPG's *fetch-keys* command to import the SeedSigner project's public key from the popular online keyserver called *Keybase.io*, into your computer's *keychain*.
```
@@ -169,7 +169,7 @@ The result must display "**Good signature**". Ignore any email addresses - *onl
<BR>
On the *last* output line, look at your *rightmost* 16 characters (the 4 blocks of 4).
**Crucially, we must now check WHO that Primary key fingerprint /ID belongs to.** We will start by looking at Keybase.io to see if it is the *SeedSigner project* 's public key or not.
**Crucially, we must now check WHO that Primary key fingerprint /ID belongs to.** We will start by looking at Keybase.io to see if it is the *SeedSigner project*'s public key or not.
<details><summary> About the warning message:</summary>
<p> Since you are about to match the outputted fingerprint/ID against the proofs at Keybase.io/SeedSigner, and thereby confirm who the pubkey really belongs to-, you can safely ignore this warning message:
@@ -184,16 +184,16 @@ On the *last* output line, look at your *rightmost* 16 characters (the 4 blocks
<details><summary> More about how the verify command works:</summary>
<p>
The verify command will attempt to decrypt the signature file (sha256.sig) by trying each public key already imported into your computer. If the public key we just imported (via fetch-keys), manages to: (a) successfully decrypt the .sig file , and (b), that result matches exactly to the clear-text equivalent (.sha256) of the .sig file, then its "a good signature"!
The verify command will attempt to decrypt the signature file (sha256.sig) by trying each public key already imported into your computer. If the public key we just imported (via fetch-keys), manages to: (a) successfully decrypt the .sig file , and (b), that result matches exactly to the clear-text equivalent (.sha256) of the .sig file, then it's "a good signature"!
Crucially, we must still manually check who *exactly* owns the Key ID which gave us that "Good signature". Thats what the warning message means- Who does the matching key really belong to? We will start by looking at keybase.io to see if it is "The SeedSigner project"'s public Key or not.
Crucially, we must still manually check who *exactly* owns the Key ID which gave us that "Good signature". That's what the warning message means- Who does the matching key really belong to? We will start by looking at keybase.io to see if it is "The SeedSigner project"'s public Key or not.
Note that it is the file hashes of .sig and .sha256 that *verify* compares, not their raw contents.
</p>
</details>
<br>
Now to determine ***who*** the Public key ID belongs to: Goto [Keybase.io/SeedSigner](https://keybase.io/seedsigner)
Now to determine ***who*** the Public key ID belongs to: Go to [Keybase.io/SeedSigner](https://keybase.io/seedsigner)
<BR>
![SS - Keybase Website PubKey visual matching1_Cropped-80pct](https://user-images.githubusercontent.com/91296549/215326193-97c84e35-5570-4e52-bf3f-e86d367c8908.jpg)
@@ -213,7 +213,7 @@ Keybase.io allows you to independently verify that the public key saved on Keyba
or,
- *without keybase (out-of-band)*: By using these 3 links directly: [Twitter](https://twitter.com/SeedSigner/status/1530555252373704707), [Github](https://gist.github.com/SeedSigner/5936fa1219b07e28a3672385b605b5d2) and [SeedSigner.com](https://seedsigner.com/keybase.txt). This method can be used if you would like to make an even deeper, independent inspection without relying on Keybase at all, or if the Keybase.io site is no longer valid or it is removed entirely.
Once you have used one of these methods, you will know if the Public Key stored on Keybase, is genuinely from the SeedSinger Project or not.
Once you have used one of these methods, you will know if the Public Key stored on Keybase, is genuinely from the SeedSigner Project or not.
</p>
</details>
<br>
@@ -225,7 +225,7 @@ If the two ID's do *not* match, then you must stop here immediately. Do not cont
### Step 2. Verifying that the *software images/binaries* are genuine
Now that you have confirmed that you do have the real SeedSigner Project's Public Key (ie the 16 characters match) - you can return to your terminal window. Running the *shasum* command, is the final verification step and will confirm (via file hashing) that the software code/image files, were also not altered since publication, or even during your download process.
(Prior to version 0.6.0 , your verify command will check the .zip file which contains the binary files.)
(Prior to version 0.6.0, your verify command will check the .zip file which contains the binary files.)
**On Linux or OSX:** Run this command
```
@@ -265,19 +265,19 @@ To write the SeedSigner software onto your MicroSD card, there are a few options
| DD Command Line Utility | Built-in to Linux and MacOS, the DD (Data Duplicator) is a tool for advanced users. If not used carefully it can accidentally format the incorrect disk! | Built-in to Linux and MacOS |
Be sure to download the software from the genuine publisher.
Either of the Etcher or Pi Imager software is recommended. Some SeedSigner users have reported a better experience with one or the other. So, if the one application doesn’t work well for your particular machine, then please try the other one.
Either of the Etcher or Pi Imager software is recommended. Some SeedSigner users have reported a better experience with one or the other. So, if the one application doesn't work well for your particular machine, then please try the other one.
<BR>
### **General Considerations:**
The writing and verify steps are very quick from version 0.6.0 upwards, so please pay close attention to your screen.
Make sure to set any write-protection physical slider on the MicroSD Card Adapter to UN-locked.
You also don’t need to pre-format the MicroSD beforehand. You *dont* need to unzip any .zip file beforehand.
Current Etcher and Pi Imager software will perform a verify action (by default) to make sure the card was written successfully! Watching for that verify step to complete successfully, can save you a lot of headaches if you later need to troubleshoot issues where your SeedSigner device doesn’t boot up at power on.
Writing the MicroSd card is also known as flashing.
You also don't need to pre-format the MicroSD beforehand. You *don't* need to unzip any .zip file beforehand.
Current Etcher and Pi Imager software will perform a verify action (by default) to make sure the card was written successfully! Watching for that verify step to complete successfully, can save you a lot of headaches if you later need to troubleshoot issues where your SeedSigner device doesn't boot up at power on.
Writing the MicroSD card is also known as flashing.
It will overwrite everything on the MicroSD card.
If the one application fails for you, then please try again using our other recommended application.
Advanced users may want to try the Linux/MacOS *DD* command instead of using Etcher or Pi Imager, however, a reminder is given that DD can overwrite the wrong disk if you are not careful !
Advanced users may want to try the Linux/MacOS *DD* command instead of using Etcher or Pi Imager, however, a reminder is given that DD can overwrite the wrong disk if you are not careful!
#### **Specific considerations for Windows users:**
Use the Pi imager software as your first choice on Windows. Windows can sometimes flag the writing of a MicroSD as risky behaviour and hence it may prevent this activity. If this happens, your writing/flashing will fail, hang or wont even begin, in which case you should to try to run the Etcher/Pi-Imager app "As administrator", (right-click and choose that option). It can also be blocked by windows security in some cases, so If you have the (non-default) *Controlled Folder Access* option set to active, try turning that *off* temporarily.
Use the Pi imager software as your first choice on Windows. Windows can sometimes flag the writing of a MicroSD as risky behaviour and hence it may prevent this activity. If this happens, your writing/flashing will fail, hang or won't even begin, in which case you should try to run the Etcher/Pi-Imager app "As administrator", (right-click and choose that option). It can also be blocked by windows security in some cases, so If you have the (non-default) *Controlled Folder Access* option set to active, try turning that *off* temporarily.
@@ -288,7 +288,7 @@ Use the Pi imager software as your first choice on Windows. Windows can sometime
### Open Pill
The Open Pill enclosure design is all about quick, simple and inexpensive depoloyment of a SeedSigner device. The design does not require any additional hardware and can be printed using a standard FDM 3D printer in about 2 hours, no supports necessary. A video demonstrating the assembly process can be found [here](https://youtu.be/gXPFJygZobEa). To access the design file and printable model, click [here](https://github.com/SeedSigner/seedsigner/tree/main/enclosures/open_pill).
The Open Pill enclosure design is all about quick, simple and inexpensive deployment of a SeedSigner device. The design does not require any additional hardware and can be printed using a standard FDM 3D printer in about 2 hours, no supports necessary. A video demonstrating the assembly process can be found [here](https://youtu.be/gXPFJygZobEa). To access the design file and printable model, click [here](https://github.com/SeedSigner/seedsigner/tree/main/enclosures/open_pill).
### Orange Pill
+5 -9
View File
@@ -1,21 +1,17 @@
# Code Structure
SeedSigner roughly follows a Model-View-Controller approach. Like in a typical web app (e.g. Flask) the `View`s can be called as needed like individual web urls. After completing display and interaction with the user, the `View` then decides where to route the user next, analogous to a web app returning a `response.redirect(url)`.
The `Controller` then ends up being quite stripped down. For example, there's no need for a web app's `urls.py` since there are no mappings from url to `View` to maintain since we're not actually using a url/http routing approach.
`View`s have to handle user interaction so there are `while True` loops that cycle between waiting for user input, gathering data, and then updating the UI components accordingly. You wouldn't find this kind of cycle in a web app because this sort of interactive user input is handled in the browser at the html/css/js level.
SeedSigner roughly follows a Model-View-Controller approach. Like in a typical web app (e.g. Flask), the `View`s can be called as needed like individual web URLs. After completing display and interaction with the user, the `View` then decides where to route the user next, analogous to a web app returning a `response.redirect(URL)`.
The `Controller` then ends up being quite stripped down. For example, there's no need for a web app's `urls.py` since there are no mappings from URL to `View` to maintain since we're not actually using a URL/HTTP routing approach.
`View`s have to handle user interaction, so there are `while True` loops that cycle between waiting for user input, gathering data, and then updating the UI components accordingly. You wouldn't find this kind of cycle in a web app because this sort of interactive user input is handled in the browser at the HTML/CSS/JS level.
* `Model`s: Store the persistent settings, the in-memory seeds, current wallet information, etc.
* `Controller`: Manages the state of the world and controls access to global resources.
* `View`s: Implementation of each screen. Prepares relevant data for display. Must also instantiate the display objects that will actually render the UI.
* `gui.screens`: Re-usable formatted UI renderers.
* `gui.screens`: Reusable formatted UI renderers.
* `gui.components`: Basic individual UI elements that are used by the `templates` such as the top nav, buttons, button lists, text displays.
In an typical webserver context the `View` would send data to an html template (e.g. Jinja) which would then dynamically populate the page with html elements like `<input>`, `<button>`, `<img>`, etc. This is analgous to our `gui.screens` constructing a UI renderer by piecing together various `gui.components` as needed.
In a typical web server context, the `View` would send data to an HTML template (e.g. Jinja) which would then dynamically populate the page with HTML elements like `<input>`, `<button>`, `<img>`, etc. This is analogous to our `gui.screens` constructing a UI renderer by piecing together various `gui.components` as needed.
`Controller` is a global singleton that any `View` can access and update as needed.
+26 -18
View File
@@ -1,37 +1,45 @@
## Debugging a Crash for advanced (technical) users
## Debugging a Crash for Advanced (Technical) Users
These instructions are intended to help users of SeedSigner provide crash exception and traceback logs to developers to aid in troubleshooting and resolving bugs.
### Testnet vs Mainnet
Whenever possible recreate a crash in testnet. This will help avoid accidently revealing private information about yourself, your bitcoin transactions, or lose any funds.
Whenever possible, recreate a crash in testnet. This will help avoid accidentally revealing private information about yourself, your Bitcoin transactions, or losing any funds.
### Network connected SeedSigner
### Network-Connected SeedSigner
If you are using SeedSigner for development and testing, then I recommend network access via ssh to view crash logs. Follow [these](https://github.com/SeedSigner/seedsigner/blob/main/docs/usb_relay.md) instructions to setup a USB relay for internet access. You can also connect your SeedSigner to Wifi if you have a rasp pi zero w/ wifi.
If you are using SeedSigner for development and testing, then we recommend network access via SSH to view crash logs. Follow [these](https://github.com/SeedSigner/seedsigner/blob/main/docs/usb_relay.md) instructions to set up a USB relay for internet access. You can also connect your SeedSigner to WiFi if you have a Raspberry Pi Zero W with WiFi.
### Airgapped debugging setup
### Airgapped Debugging Setup
If you are using SeedSigner for mainnet transactions, then do not connect your device to a network or the internet. Instead connect your SeedSigner to a HDMI display (without internet) and a USB keyboard. This will require an HDMI adapter and micro USB to USB A adapter. Plug in the HDMI display and keyboard before powering on SeedSigner. The password for the SeedSigner pi user is `raspberry`.
If you are using SeedSigner for mainnet transactions, then do not connect your device to a network or the internet. Instead, connect your SeedSigner to an HDMI display (without internet) and a USB keyboard. This will require an HDMI adapter and a micro USB to USB A adapter. Plug in the HDMI display and keyboard before powering on SeedSigner. The password for the SeedSigner pi user is `raspberry`.
### Debugging steps
### Debugging Steps
At this point you should be signed into the pi user either on a HDMI display (via command line) or a ssh connection.
At this point, you should be signed into the pi user either on an HDMI display (via command line) or an SSH connection.
Follow these steps to setup a debug session.
Follow these steps to set up a debug session:
`cd seedsigner/src`
1. Navigate to the source directory:
```bash
cd seedsigner/src
```
`nano settings.ini`
2. Edit the settings file:
```bash
nano settings.ini
```
in nano editor change `debug = False` to `debug = True` (case sensitive). Save and exit settings.ini.
3. In the nano editor, change `debug = False` to `debug = True` (case sensitive). Save and exit settings.ini.
stop the seedsigner systemd process by running
4. Stop the SeedSigner systemd process:
```bash
sudo systemctl stop seedsigner.service
```
`sudo systemctl stop seedsigner.service`
now start the python app manually by running
`python3 main.py`
5. Start the Python app manually:
```bash
python3 main.py
```
SeedSigner should now be up and running. Keep it connected to the display and keyboard. Recreate the steps to cause the crash. The traceback log and exception will be displayed on the HDMI display.
+20 -15
View File
@@ -3,12 +3,16 @@
### Quickly generate a new seed to test with
Generate a new 12- or 24-word seed via [https://iancoleman.io/bip39/](https://iancoleman.io/bip39/).
Access a `python3` environment that has the `embit` library installed (e.g. your own local machine, ssh into the SeedSigner, etc)
Access a `python3` environment that has the `embit` library installed (e.g., your own local machine, SSH into the SeedSigner, etc.).
Start a python REPL session by just typing: `python3`
Paste in the following but insert your newly generated mnemonic:
Start a `python3` REPL session by typing:
```bash
python3
```
Paste in the following code (replace the seed phrase with your newly generated mnemonic):
```python
from embit import bip39
seed_phrase = "smoke chimney announce candy glory tongue refuse fatigue cricket once consider beef treat urge wing deny gym robot tobacco adult problem priority wheat diagram"
data = ""
@@ -19,7 +23,7 @@ for word in seed_phrase.split(" "):
print(data)
```
For the seed in the snippet, you should see:
For the example seed phrase above, you should see:
```
163803200074026607961827144306700411123603780160185419152013046908321497181700301371136719990487
```
@@ -28,20 +32,20 @@ Take the output and paste it into a [QR code generator](https://www.the-qrcode-g
Start up SeedSigner's UI to import a seed from a QR code. Scan the new QR code and you're good to go!
# Advanced developer notes
## Backup an SD card
You can back up and restore any size SD card but the process is a little inefficient so the bigger the source SD card, the bigger the backup will be and the longer it'll take to create (and even longer to image back to a new SD card), even if most of the card is blank.
You can back up and restore any size SD card, but the process is a little inefficient. The bigger the source SD card, the bigger the backup will be and the longer it'll take to create (and even longer to image back to a new SD card), even if most of the card is blank.
You can restore a backup image to an SD card of the same or larger size. So it's strongly recommended to do repetitive development work on a smaller card that's easier to backup and restore. Once the image is stabilized, then write it to a bigger card, if necessary (that being said, there's really no reason to use a large SD card for SeedSigner. An 8GB SD card is more than big enough).
You can restore a backup image to an SD card of the same or larger size. It's strongly recommended to do repetitive development work on a smaller card that's easier to backup and restore. Once the image is stabilized, then write it to a bigger card, if necessary (that being said, there's really no reason to use a large SD card for SeedSigner. An 8GB SD card is more than big enough).
Insert the SD card into a Mac/Linux machine and create a compressed img file.
### Steps to create a backup:
First verify the name of your SD card:
1. Insert the SD card into a Mac/Linux machine
2. Verify the name of your SD card:
```
```bash
# Mac:
diskutil list
@@ -49,14 +53,15 @@ diskutil list
sudo fdisk -l
```
It will most likely be `/dev/disk1` on most systems.
The device will most likely be `/dev/disk1` on most systems.
Now we use `dd` to clone and `gzip` to compress it. Note that we reference the SD card by adding an `r` in front of the disk name. This speeds up the cloning considerably.
3. Create a compressed backup using `dd` and `gzip`. Note that we reference the SD card by adding an `r` in front of the disk name to speed up the cloning process:
```
```bash
sudo dd if=/dev/rdisk1 conv=sparse bs=4m | gzip -9 > seedsigner.img.gz
```
The process should take about 15 minutes and will typically generate a roughly 1.1GB image.
To restore from your backup image, just use the Raspberry Pi Imager. Remember that you can only write it to an SD card of equal or greater size than the original SD card.
### Restoring from backup
To restore from your backup image, use the Raspberry Pi Imager. Remember that you can only write it to an SD card of equal or greater size than the original SD card.
+19 -18
View File
@@ -1,26 +1,27 @@
# Verifying dice seed generation
The intention of this documentation is to describe how to verify the seed generation code used in SeedSigner against other independent tools, to prove that they all generate the same results, despite them using different programming languages and code libraries.<br><br>
As it is an important step to verify all software releases being used to ensure that the installation files downloaded have not been compromised, the same is true especially for the seed generation procedure which unknowingly might not work as expected due to bugs or even on purpose.<br><br>
This guide describes how this can be achieved.<br><br>
As usual: Don't Trust, Verify!<br>
<br><br>
**Note:**<br>
**Do NOT use this with any seed you want to use later with real funds. This exercise is only for checking that the independent codebases get to the same end result!**<br>
**However, if you do want to check your real seedphrases you should download the Iancoleman and/or Bitcoiner.Guide tools onto an airgapped, ephemeral computer (e.g. using tails-OS) and perform these tests on there. Destroy/abandon the TailsOS afterwards.**<br>
The intention of this documentation is to describe how to verify the seed generation code used in SeedSigner against other independent tools, to prove that they all generate the same results, despite them using different programming languages and code libraries.
As it is an important step to verify all software releases being used to ensure that the installation files downloaded have not been compromised, the same is true especially for the seed generation procedure which unknowingly might not work as expected due to bugs or even on purpose.
This guide describes how this can be achieved.
As usual: Don't Trust, Verify!
**Note:**
**Do NOT use this with any seed you want to use later with real funds. This exercise is only for checking that the independent codebases get to the same end result!**
**However, if you do want to check your real seed phrases you should download the Ian Coleman and/or Bitcoiner.Guide tools onto an airgapped, ephemeral computer (e.g. using Tails-OS) and perform these tests on there. Destroy/abandon the Tails-OS afterwards.**
**Never input seed phrases that you intend to use to store real funds onto an internet-connected computer!!!**
<br><br><br>
## 99 Dice Rolls / 24 Seed Words Example
The following 99 dice roll results are used in the verification steps as an example for a 24 words seed:<br>
The following 99 dice roll results are used in the verification steps as an example for a 24-word seed:<br>
> 655152231316521321611331544441236164664431121534415633526456254462245546236542364246312613322234612
The corresponding 24 seed words are:<br>
> eyebrow obvious such suggest poet seven breeze blame virtual frown dynamic donor harsh pigeon express broccoli easy apology scatter force recipe shadow claim radio
(Scroll down near the end to see result values for a 50 dice rolls / 12 seed words example)
<br><br><br>
## Creating seed via Dice rolls in SeedSigner (here v0.6.0)
@@ -56,7 +57,7 @@ Keep the SeedSigner open and the newly created seed still loaded as we will need
## Create new wallet from seed in Sparrow Wallet to see xpub/zpub and addresses
Go to https://www.sparrowwallet.com/download/ and download the release version supported by your operating system.<br><br>
Open Sparrow Wallet, go to 'File' menu and select 'New Wallet'. Enter a name (e.g. test), and click 'Create Wallet'.<br><br>
Open Sparrow Wallet, go to the 'File' menu and select 'New Wallet'. Enter a name (e.g. test), and click 'Create Wallet'.<br><br>
Click 'Airgapped Hardware Wallet' (1) and click on the 'Scan' button in the SeedSigner entry (2) which will open the camera scan screen:<br>
<kbd><img src="img/dicedoc/sparrow_wallet_1.png"></kbd>
@@ -84,7 +85,7 @@ Go to https://iancoleman.io/bip39 and check 'Show entropy details' (1):<br>
<br>
Make sure to check (1) 'Hex' and (2) '24 Words' as 'Mnemonic Length'.<br>
(Do not use 'dice' format because dice 6 will be replaced by 0).<br>
Then enter the 99 dices numbers in (3). The corresponding seed words are shown in (4):<br>
Then enter the 99 dice numbers in (3). The corresponding seed words are shown in (4):<br>
<kbd><img src="img/dicedoc/coleman_verify.png"></kbd>
<br><br>
The 24 seed words are the same in SeedSigner and the Ian Coleman tool.
@@ -144,7 +145,7 @@ Compare to zpub in Sparrow:<br>
<kbd><img src="img/dicedoc/sparrow_zpub.png"></kbd>
<br>
Zpub is the same as shown in SeedSigner, Sparrow and Ian Colemand tool.
Zpub is the same as shown in SeedSigner, Sparrow and Ian Coleman tool.
<br><br>
**Addresses:**<br>
Scroll down a little bit where the receive addresses are shown and compare to the ones generated in Sparrow ('Addresses' tab of the wallet):<br>
@@ -163,10 +164,10 @@ Check that the change addresses all match.
## 50 Dice Rolls / 12 Seed Words Example
SeedSigner supports the creation of mnenomic seeds both with 12 or 24 seed words corresponding to 50 or 99 dice rolls. Below are some example result values for using 50 dice rolls only.<br><br>
All the steps shown can be executed the same way, just select the '12 words (50 rolls)' option in SeedSigner and change the 'Mnenomic Length' dropdown boxes in both web tools to '12 Words'.<br><br>
SeedSigner supports the creation of mnemonic seeds both with 12 or 24 seed words corresponding to 50 or 99 dice rolls. Below are some example result values for using 50 dice rolls only.<br><br>
All the steps shown can be executed the same way, just select the '12 words (50 rolls)' option in SeedSigner and change the 'Mnemonic Length' dropdown boxes in both web tools to '12 Words'.<br><br>
50 dice roll results as an example for a 12 words seed:<br>
50 dice roll results as an example for a 12-word seed:<br>
> 65515223131652132161133154444123616466443112153441
The corresponding 12 seed words are:<br>
@@ -246,7 +247,7 @@ python3 mnemonic.py -h
python3 mnemonic.py coins 1111100111...
# 256 coin flips / 24-word mnemonic
python mnemonic.py coins 0010111010...
python3 mnemonic.py coins 0010111010...
# GENERATE 50 random dice rolls / 12-word mnemonic
python3 mnemonic.py dice rand12
+4 -4
View File
@@ -1,8 +1,8 @@
# SeedSigner Electrum seed phrase support
# SeedSigner Electrum Seed Phrase Support
SeedSigner supports loading of [Electrum's Segwit seed phrases](https://electrum.readthedocs.io/en/latest/seedphrase.html#electrum-seed-version-system). This is considered an Advanced feature that is disabled by default.
SeedSigner supports loading of [Electrum's SegWit seed phrases](https://electrum.readthedocs.io/en/latest/seedphrase.html#electrum-seed-version-system). This is considered an Advanced feature that is disabled by default.
To load an Electrum Segwit seed phrase, first enable Electrum seed support in Settings -> Advanced -> Electrum seed support. After this option is enabled, the user will now be able to enter an Electrum seed phrase by selecting "Enter Electrum seed" in the Load Seed screen.
To load an Electrum SegWit seed phrase, first enable Electrum seed support in Settings -> Advanced -> Electrum seed support. After this option is enabled, the user will now be able to enter an Electrum seed phrase by selecting "Enter Electrum seed" in the Load Seed screen.
Some SeedSigner functionality is deliberately disabled when using an Electrum mnemonic:
@@ -11,5 +11,5 @@ Some SeedSigner functionality is deliberately disabled when using an Electrum mn
- SeedQR backups
- Since Electrum seeds are not supported by other SeedQR implementations, it would be dangerous to use SeedQR as a backup tool for Electrum seeds and is thus disabled
- Custom derivations
- Hard coded derivation path and script types in SeedSigner to match Electrum wallet software. These are m/0h for single sig and m/1h for multisig
- Hard-coded derivation path and script types in SeedSigner to match Electrum wallet software. These are m/0h for single sig and m/1h for multisig
- User-chosen custom derivations are thus not supported for Electrum seeds
+12 -12
View File
@@ -6,28 +6,28 @@ Current focus: v0.5.0 preview releases.
## v0.5.0 Pre-Release 1.x
* Scan SeedQR / CompactSeedQR
* Scan SeedQR/CompactSeedQR
* Add/Edit passphrase
* View seed words w/configurable warnings
* Export xpub w/configurable warnings and flow determined by Settings
* View seed words with configurable warnings
* Export xpub with configurable warnings and flow determined by Settings
* Scan PSBT
* Full PSBT review screens
* "Full Spend" (no change) warning
* Fully verify PSBT change addrs
* Fully verify PSBT change addresses
* Send signed PSBT via QR
* QR display dimming/brightness UP/DOWN
* Subset of configurable Settings; persistent Settings storage
* SettingsQR integration proof-of-concept
Screens will be functional but not necessarily in their final presentation state (icons, text, positioning, etc).
Screens will be functional but not necessarily in their final presentation state (icons, text, positioning, etc.).
## v0.5.0 Pre-Release 2.x
* Existing screen refinement (visual presentation, text, etc)
* Existing screen refinement (visual presentation, text, etc.)
* Create new seed via image entropy
* Manual mnemonic seed word entry
* 12th/24th word calc
* SeedQR/CompactSeedQR manual transcription UI w/configurable UI style (dots vs grid)
* 12th/24th word calculation
* SeedQR/CompactSeedQR manual transcription UI with configurable UI style (dots vs grid)
* Single sig address scan and verification
* SettingsQR standalone UI refinement
* Fix broken tests
@@ -52,16 +52,16 @@ All of the above!
## Beyond v0.5.0
These features will not be included in the initial v0.5.0 release and will have varying degrees of priority for subsequent releases (or possibly not at all).
* Multisig wallet descriptor QR scan(?) and addr verification(?)
* Sign taproot txs
* Multisig wallet descriptor QR scan(?) and address verification(?)
* Sign taproot transactions
* Multi-language support (Transifex free for open source projects)
* Multisig: sign PSBT with multiple keys at once.
* Multisig: sign PSBT with multiple keys at once
* Custom OS, possibly with swappable SD card PSBT and multisig wallet descriptor storage
* Decoy game mode at launch (Snake, Tetris, Sudoku...?)
* BIP-39 wordlists in additional languages
* Address message signing
* UI color scheme customization
* Specify missing entropy for 12th/24th word calc
* Specify missing entropy for 12th/24th word calculation
# v0.6 and Beyond...?
+5 -5
View File
@@ -5,18 +5,18 @@ Older Raspberry Pi devices have a smaller GPIO header, 26 pin as opposed to the
## Hardware Changes
A suggested remapping can be found here:
![Remapped Pins Shematic](./img/legacy_hardware_remapped_pins.jpg)
![Remapped Pins Schematic](./img/legacy_hardware_remapped_pins.jpg)
This remapping can be done by soldering wires on to the Waveshare hat as below:
![Remapped Pins Photo](./img/legacy_hardware_remapped_pins_photo.jpg)
Alternatively, you could do this by connecting the LCD hat on with individual breadboard jumper wires.
Alternatively, you could do this by connecting the LCD hat with individual breadboard jumper wires.
Once you have re-mapped the pins, it is advised to do an IO Test to ensure that everything works.
Once you have re-mapped the pins, it is advised to do an I/O Test to ensure that everything works.
**Warning: Some of the GPIO pins on contain 5 volt output. Raspberry Pi GPIO pins are NOT 5V tolerant, meaning that if you accidentally connect a 5V supply pin to a GPIO input pin, you risk permanent damage.**
**Warning: Some of the GPIO pins contain 5 volt output. Raspberry Pi GPIO pins are NOT 5V tolerant, meaning that if you accidentally connect a 5V supply pin to a GPIO input pin, you risk permanent damage.**
## Software Changes
The Seedsigner software will automatically detect which hardware revision you are using and if the older hardware is detected, will remap the software to match the above modifications to the Waveshare hat.
If you are using a pre-built Seedsigner image that hasn't yet has this incorporated, you can simply take the file "buttons.py" (/src/seedsigner/hardware/ int his repository) and overwrite same file on your Seedsigner SD card. (The easiest way to do this is to copy it on to the /boot/ partitition of the SD card then copy it over via the command line while connected to your Pi via monitor+keyboard) O
If you are using a pre-built Seedsigner image that hasn't yet had this incorporated, you can simply take the file "buttons.py" (/src/seedsigner/hardware/ in this repository) and overwrite the same file on your Seedsigner SD card. (The easiest way to do this is to copy it to the /boot/ partition of the SD card then copy it over via the command line while connected to your Pi via monitor+keyboard.)
+7 -7
View File
@@ -2,7 +2,7 @@
### Scanning QR Codes
SeedSigner supports scanning the following QR formats
SeedSigner supports scanning the following QR formats:
Animated QR Formats:
- PSBT
@@ -15,15 +15,15 @@ Static QR Formats:
- Base64 (if the PSBT byte size is too large, SS may have trouble scanning)
- Seed
- [SeedSigner SeedQR](seed_qr/README.md) format
- A 48 or 96 length string of numbers representing a bip39 wordlist (all wordlist languages supported). The numeric sequence is a concatenation of four-digit, zero-padded segments. Each four-digit segment represents a bip39 word expressed by a zero-indexed position in the wordlist. For example "0000" is abandon in the english bip39 wordlist.
- A 48 or 96 length string of numbers representing a BIP39 wordlist (all wordlist languages supported). The numeric sequence is a concatenation of four-digit, zero-padded segments. Each four-digit segment represents a BIP39 word expressed by a zero-indexed position in the wordlist. For example, "0000" is "abandon" in the English BIP39 wordlist.
- [SeedSigner CompactSeedQR](seed_qr/README.md) format
- The 128- or 256-bit entropy encoded as a binary QR.
- English Bip39 Mnemonic words separated by a space. Currently only supports 12 and 24 word seeds.
- English Bip39 Mnemonic with only first 4 letters seperated by a space. Currently only supports 12 and 24 word seeds.
- The 128- or 256-bit entropy encoded as a binary QR
- English BIP39 Mnemonic words separated by a space (currently only supports 12 and 24 word seeds)
- English BIP39 Mnemonic with only first 4 letters separated by a space (currently only supports 12 and 24 word seeds)
### Displaying QR Codes
SeedSigner supports displaying QR's in the following formats
SeedSigner supports displaying QR codes in the following formats:
Animated QR Formats:
- PSBT
@@ -33,4 +33,4 @@ Animated QR Formats:
Static QR Formats:
- Seed
- SeedSigner Seed QR format
- A 48 or 96 length string of numbers representing a bip39 wordlist (all wordlist languages supported). The numeric sequence is a concatination of four-digit zero padded segments. Each four-digit segment represents a bip39 word expressed by a zero-indexed position in the wordlist. For example "0000" is abandon in the english bip39 wordlist.
- A 48 or 96 length string of numbers representing a BIP39 wordlist (all wordlist languages supported). The numeric sequence is a concatenation of four-digit, zero-padded segments. Each four-digit segment represents a BIP39 word expressed by a zero-indexed position in the wordlist. For example, "0000" is "abandon" in the English BIP39 wordlist.
+22 -25
View File
@@ -1,23 +1,23 @@
# Raspberry Pi OS Local Dev Build Instructions
Since v0.6.0, official releases use our custom [SeedSigner OS](https://github.com/SeedSigner/seedsigner-os/) However, project contributors looking to do rapid development cycles typically use the older Raspberry Pi OS that we had previously built on prior to v0.6.0. If you're here to set up your SeedSigner for local development, continue reading.
Since v0.6.0, official releases use our custom [SeedSigner OS](https://github.com/SeedSigner/seedsigner-os/). However, project contributors looking to do rapid development cycles typically use the older Raspberry Pi OS that we had previously built on prior to v0.6.0. If you're here to set up your SeedSigner for local development, continue reading.
Begin by acquiring the latest 32-bit, Buster-based Raspberry Pi Lite operating system. This guide was tested using the version dated 2023-05-03; which can be found here:
Begin by acquiring the latest 32-bit, Buster-based Raspberry Pi Lite operating system. This guide was tested using the version dated 2023-05-03, which can be found here:
https://downloads.raspberrypi.org/raspios_oldstable_lite_armhf/images/raspios_oldstable_lite_armhf-2023-05-03/
SeedSigner does not work any of the more recent versions of Debian. This is a known limitation and there are open tickets to track the progress of this ([Debian 11 ticket](https://github.com/SeedSigner/seedsigner/issues/431), [Debian 12 ticket](https://github.com/SeedSigner/seedsigner/issues/430)). This guide does not work on the 64-bit versions of Buster, however pull requests to update it to be compatible are welcome.
SeedSigner does not work with any of the more recent versions of Debian. This is a known limitation and there are open tickets to track the progress of this ([Debian 11 ticket](https://github.com/SeedSigner/seedsigner/issues/431), [Debian 12 ticket](https://github.com/SeedSigner/seedsigner/issues/430)). This guide does not work on the 64-bit versions of Buster, however pull requests to update it to be compatible are welcome.
Best practice is to verify the downloaded file containing the Raspberry Pi Lite OS matches the published SHA256 hash of the file; for additional reference that hash is: 3d210e61b057de4de90eadb46e28837585a9b24247c221998f5bead04f88624c. After verifying the file's data integrity, you can decompress the .tar.xz file to obtain the operating system image that it contains. You can then use Balena's Etcher tool (https://www.balena.io/etcher/) to write the Raspberry Pi Lite software image to a memory card (4 GB or larger). It's important to note that an image authoring tool must be used (the operating system image cannot be simply copied into a file storage partition on the memory card).
The manual SeedSigner installation and configuration process requires an internet connection on the Pi to download the necessary libraries and code.
If your Pi does not have onboard wifi, you have two options:
If your Pi does not have onboard WiFi, you have two options:
1. Run these steps on a separate Raspberry Pi 2/3/4 or Zero W which does have onboard Wi-Fi to connect to the internet, and then move the SD card over to the non Wi-Fi enabled Pi when complete.
2. OR configure the non Wi-Fi enabled Pi directly by relaying through your computer's internet connection over USB. See instructions [here](usb_relay.md).
1. Run these steps on a separate Raspberry Pi 2/3/4 or Zero W which does have onboard WiFi to connect to the internet, and then move the SD card over to the non WiFi enabled Pi when complete.
2. OR configure the non WiFi enabled Pi directly by relaying through your computer's internet connection over USB. See instructions [here](usb_relay.md).
If your Pi does have onboard Wi-Fi, then using the Rasberry Pi Imager software will allow you to easily configure your Pi's Wi-Fi connection, as well as simultaneously write the image file. That will make your initial SSH into the Pi much easier.
Use the Pi's onboard Wi-Fi only if you are setting up a local development environment, never for real funds or binary image creation.
If your Pi does have onboard WiFi, then using the Raspberry Pi Imager software will allow you to easily configure your Pi's WiFi connection, as well as simultaneously write the image file. That will make your initial SSH into the Pi much easier.
Use the Pi's onboard WiFi only if you are setting up a local development environment, never for real funds or binary image creation.
For the following steps you'll need to either connect a keyboard & monitor to the network-connected Raspberry Pi you are working with, or SSH into the Pi if you're familiar with that process.
@@ -60,8 +60,7 @@ Set the following:
When you exit the System Configuration tool, you will be prompted to reboot the system; allow the system to reboot and continue with these instructions.
Each command should be run individually,unless its specified as a multi-line command.
Each command should be run individually, unless it's specified as a multi-line command.
### Change the default password
Change the system's default password from the default "raspberry". Run the command:
```bash
@@ -69,7 +68,6 @@ passwd
```
You will be prompted to enter the current password ("raspberry") and then to enter a new password twice. In our prepared release image, the password used is `AirG@pped!`.
### Install python3.10
```bash
# install compiler dependencies; takes ~1 minute on a Pi Zero 1.3
@@ -106,7 +104,6 @@ sudo apt autoremove -y
sudo apt install python3-apt -y
```
### Install dependencies
Copy this entire box and run it as one command (~15 minutes on a Pi Zero 1.3):
```bash
@@ -313,9 +310,9 @@ First find your current `nameserver`:
sudo cat /etc/resolv.conf
```
This is the address of your local machine that is connected to your SeedSigner via usb (or it'll be the wifi router's address if you're using a Raspi with wifi and are keeping it enabled for `ssh` access).
This is the address of your local machine that is connected to your SeedSigner via USB (or it'll be the WiFi router's address if you're using a Raspberry Pi with WiFi and are keeping it enabled for `ssh` access).
Set a static ip: `sudo nano /etc/dhcpcd.conf` and add to the end:
Set a static IP: `sudo nano /etc/dhcpcd.conf` and add to the end:
```
interface usb0
static ip_address=192.168.1.200/24
@@ -323,16 +320,16 @@ static routers=192.168.1.254
static domain_name_servers=192.168.1.254
```
* `interface` will be `usb0` for usb connections; `wlan0` for wifi.
* `static ip_address` is the ip address you want the SeedSigner to use. It should match the `nameserver` ip you found above for all but the last part of the ip (note: the `/24` should always be included as-is).
* `static routers` should be your `nameserver` ip.
* `static domain_name_servers` should also be the `nameserver` ip.
* `interface` will be `usb0` for USB connections; `wlan0` for WiFi.
* `static ip_address` is the IP address you want the SeedSigner to use. It should match the `nameserver` IP you found above for all but the last part of the IP (note: the `/24` should always be included as-is).
* `static routers` should be your `nameserver` IP.
* `static domain_name_servers` should also be the `nameserver` IP.
`CTRL-X` and `y` to save changes.
After your next reboot, access this SeedSigner using its new static ip:
After your next reboot, access this SeedSigner using its new static IP:
```bash
# Use the static ip you set above:
# Use the static IP you set above:
ssh pi@192.168.1.200
# But the hostname will still work, too:
@@ -350,7 +347,7 @@ host seedsigner.local
User pi
LogLevel QUIET
# Set this to the static ip you set above:
# Set this to the static IP you set above:
host 192.168.1.200
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
@@ -360,7 +357,7 @@ host 192.168.1.200
The first entry prevents warnings for the default `pi@seedsigner.local` connections.
The second entry does the same for a specific static ip; you'll want this if you configure all your SeedSigners to use the same static ip.
The second entry does the same for a specific static IP; you'll want this if you configure all your SeedSigners to use the same static IP.
`CTRL-X` and `y` to save changes.
@@ -372,7 +369,7 @@ run `ssh-copy-id` with the same values that you connect via `ssh`:
```bash
ssh-copy-id pi@seedsigner.local
# or if you're connecting over static ip, something like:
# or if you're connecting over static IP, something like:
ssh-copy-id pi@192.168.1.200
```
@@ -381,8 +378,8 @@ You'll be prompted to enter the password to complete it.
_Note: If you don't have any ssh keys on your local machine, you'll need to create a set with `ssh-keygen -t ed25519 -C "your_email@example.com"`. Then try running `ssh-copy-id` again._
## Disable wifi/Bluetooth when using other Raspi boards
If you plan to use your installation on a Raspberry Pi that is not a Zero version 1.3, but rather on a Raspberry Pi that has WiFi and Bluetooth capabilities, it is a good idea to disable the following WiFi & Bluetooth, as well as other relevant services (assuming you are not creating this installation for testing/development purposes). Enter the followiing commands to disable WiFi, Bluetooth, & other relevant services:
## Disable WiFi/Bluetooth when using other Raspberry Pi boards
If you plan to use your installation on a Raspberry Pi that is not a Zero version 1.3, but rather on a Raspberry Pi that has WiFi and Bluetooth capabilities, it is a good idea to disable the following WiFi & Bluetooth, as well as other relevant services (assuming you are not creating this installation for testing/development purposes). Enter the following commands to disable WiFi, Bluetooth, & other relevant services:
```bash
sudo systemctl disable bluetooth.service
sudo systemctl disable wpa_supplicant.service
+6 -6
View File
@@ -2,7 +2,7 @@
[SeedSigner](https://github.com/SeedSigner/seedsigner/) is an open source, DIY, fully-airgapped Bitcoin hardware wallet that wipes all private data from memory each time it's turned off. That means users need to re-enter their mnemonic seed phrase each time they use it.
To speed up this key entry process we have defined a way to encode a BIP-39 mnemonic seed phrase as a QR code that can be instantly scanned into a SeedSigner or potentially any other Bitcoin hardware wallet that has a camera.
To speed up this key entry process, we have defined a way to encode a BIP-39 mnemonic seed phrase as a QR code that can be instantly scanned into a SeedSigner or potentially any other Bitcoin hardware wallet that has a camera.
The approach is specifically designed to encode the minimum possible amount of data in order to keep the resulting QR code small enough that it can be transcribed *by hand*. This sounds ridiculous at first, but remember that this is secret data that should never be stored in any digital medium. And even printers present some additional risk vectors.
@@ -26,7 +26,7 @@ Each word comes from a [list of 2048 words](https://github.com/bitcoin/bips/blob
For example, "tomato" is the 1,825th word in the list.
But code always starts counting list items with zero. So the index of "tomato" is actually `1824` (if you're looking at the github wordlist line numbers, just remember to always subtract one).
But code always starts counting list items with zero. So the index of "tomato" is actually `1824` (if you're looking at the GitHub wordlist line numbers, just remember to always subtract one).
So we can transcode a 12-word seed into a series of indices:
@@ -264,7 +264,7 @@ But there are other tradeoffs to consider.
## Recoverability
If you lose your SeedSigner or somehow the project is abandoned or banned, how will you read back your SeedQR?
With the Standard SeedQR format this is trivial--any smartphone can decode the numeric digit stream. But the CompactSeedQR's raw byte data is not decipherable in the same way. Most QR readers today assume the data is either alphanumeric or human-readable numeric data. Because of this assumption, they misinterpret the binary format data:
With the Standard SeedQR format, this is trivial--any smartphone can decode the numeric digit stream. But the CompactSeedQR's raw byte data is not decipherable in the same way. Most QR readers today assume the data is either alphanumeric or human-readable numeric data. Because of this assumption, they misinterpret the binary format data:
<table align="center">
<tr>
@@ -283,7 +283,7 @@ It's just the above process in reverse:
# Separate out into 4-digit individual indices
1924 0222 0235 1743 0631 1124 0378 1770 0641 1980 1290 1210
# Look up each BIP-39 index number (index+1 if using the github list!)
# Look up each BIP-39 index number (index+1 if using the GitHub list!)
1. vacuum 1924
2. bridge 222
3. buddy 235
@@ -298,7 +298,7 @@ It's just the above process in reverse:
12. nuclear 1210
```
It would be much more difficult to manually recreate your seed from a CompactSeedQR. Tools like [zxing.org](https://zxing.org/w/decode.jspx) or [ZBar](https://zbar.sourceforge.net/) can help you get the binary data out as a hexidecimal string:
It would be much more difficult to manually recreate your seed from a CompactSeedQR. Tools like [zxing.org](https://zxing.org/w/decode.jspx) or [ZBar](https://zbar.sourceforge.net/) can help you get the binary data out as a hexadecimal string:
<img src="img/zxing_screenshot.png">
@@ -313,7 +313,7 @@ Conversely, having limited support for reading binary QR codes and the complicat
# Some Additional Notes on QR Codes
Our main use case is to be able to quickly initialize a SeedSigner with your mnemonic seed phrase. But using a QR code as your key loader--or even as your permanent backup etched in metal--has other advantages.
QR codes are ubiquitous now so plenty of hardware and software exists to read and generate them.
QR codes are ubiquitous now, so plenty of hardware and software exists to read and generate them.
QR codes have built-in error correction. The "L" error correction mode is described as having a roughly 7% correction rate.
+29 -31
View File
@@ -1,6 +1,6 @@
## Relaying internet access to the Pi Zero 1.3 over USB
Note that this is an optional, alternate way to initialize your SeedSigner. The default method is to work on a separate Raspberry Pi device that has internet access. Be aware that by enabling internet access over USB you are obviously creating a link to the outside world that this project seeks to avoid.
Note that this is an optional, alternate way to initialize your SeedSigner. The default method is to work on a separate Raspberry Pi device that has internet access. Be aware that by enabling internet access over USB, you are creating a link to the outside world that this project seeks to avoid.
If you use this setup route, we recommend that you disable internet access over USB when these steps are complete.
@@ -8,17 +8,17 @@ If you use this setup route, we recommend that you disable internet access over
### Get started
Insert the SD card with your Raspberry Pi OS image into a regular computer. Open a terminal window (macOS: Terminal; Windows: Command Prompt) and navigate to the SD card:
```
# mac/Linux:
```bash
# macOS/Linux:
cd /Volumes/boot
# Windows (alter with correct drive letter):
cd e:
```
We need to create an empty file called "ssh" to enable us to remotely terminal into the Pi via SSH.
```
# mac/Linux:
We need to create an empty file called `ssh` to enable remote terminal access to the Pi via SSH:
```bash
# macOS/Linux:
touch ssh
# Windows:
@@ -29,8 +29,8 @@ type nul > ssh
Now we have some incomprehensible configuration steps to set up the internet access relay.
Edit `config.txt`:
```
# mac/Linux:
```bash
# macOS/Linux:
nano config.txt
# Windows:
@@ -39,17 +39,15 @@ notepad config.txt
Add `dtoverlay=dwc2` to the end of `config.txt`. Exit and save changes (CTRL-X, then "y" in nano).
Alternatively, add to `config.txt` via the command line:
```
# mac/Linux/Windows:
```bash
# macOS/Linux/Windows:
echo dtoverlay=dwc2 >> config.txt
```
Next, edit `cmdline.txt`:
```
# mac/Linux:
```bash
# macOS/Linux:
nano cmdline.txt
# Windows:
@@ -68,7 +66,7 @@ If you are on Linux, you need to first [set a static IP](#set-a-static-ip-on-lin
Eject the SD card and insert it into your Pi Zero 1.3. Plug a USB cable into your computer and into the Pi's USB connector that is closer to the center. It will draw power from the USB cable and begin powering up.
The Pi will take a minute or so to boot up its OS. After waiting a bit, try to communicate with the Pi over SSH:
```
```bash
# Manual builds:
ssh pi@raspberrypi.local
@@ -83,7 +81,7 @@ ECDSA key fingerprint is SHA256:go4yVgii1GcvyxzhOe03atLn5bl2NhZlOR04tJHBo+k.
Are you sure you want to continue connecting (yes/no/[fingerprint])?
```
At the password prompt enter the Pi's default password: `raspberry`
At the password prompt, enter the Pi's default password: `raspberry`
If you now see the Pi's command prompt, you're in!
@@ -96,7 +94,7 @@ This is a security risk - please login as the 'pi' user and type 'passwd' to set
```
If someone savvy got access to your SeedSigner, they could sign into it and potentially upload malicious code. To add an extra layer of protection, change the default 'pi' user's password now by typing `passwd`:
```
```bash
pi@raspberrypi:~ $ passwd
Changing password for pi.
Current password:
@@ -105,7 +103,6 @@ Retype new password:
passwd: password updated successfully
```
## Configure host computer to share internet access with the Pi
### macOS
@@ -126,7 +123,7 @@ Now go to the "Sharing" system settings. Click on "Internet Sharing" and check t
Click the "Internet Sharing" checkbox to activate.
Back at your SSH terminal, test the connection:
```
```bash
ping 8.8.8.8
```
@@ -143,7 +140,7 @@ see: https://www.circuitbasics.com/raspberry-pi-zero-ethernet-gadget/
### Linux
To enable IP forwarding on your Host:
```
```bash
nano /etc/sysctl.conf
```
@@ -171,11 +168,12 @@ What you will need:
_Note: Remember to remove the brackets. For example, `ip_address=<rpi_ip>` should be written as: `ip_address=192.168.21.21`_
#### On the SD card
```
```bash
cd rootfs/etc
nano dhcpcd.conf
```
At the end of the file, add the following lines.
At the end of the file, add the following lines:
```
interface usb0
static ip_address=<rpi_ip>/24
@@ -192,7 +190,7 @@ Type `lsusb` to see if your Pi Zero is properly connected. Look for `Ethernet/RN
![Static IP on the seedsigner Interface](img/usb_relay_linux_01.png)
Set a name for your new Interface:
```
```bash
nano /etc/systemd/network/10-rename-rpi0.link
```
@@ -204,8 +202,8 @@ Property=ID_VENDOR_ID=0525 "ID_MODEL_ID=a4a2"
Name=seedsigner0
```
To give your Host a static ip:
```
To give your Host a static IP:
```bash
nano /etc/network/interfaces.d/seedsigner
```
@@ -235,8 +233,8 @@ Return to the main [README](../README.md) and complete the setup steps. But reme
Power down the SeedSigner and remove the SD card. Put the SD card back into your computer and use a terminal to navigate to the `boot` drive (same process as above).
Edit `config.txt`:
```
# mac/Linux:
```bash
# macOS/Linux:
nano config.txt
# Windows:
@@ -247,8 +245,8 @@ Delete the `dtoverlay=dwc2` line that we added to the end of the file. Exit and
Edit `cmdline.txt`:
```
# mac/Linux:
```bash
# macOS/Linux:
nano cmdline.txt
# Windows:
@@ -262,8 +260,8 @@ Eject the SD card and put it back in the SeedSigner. Connect the SeedSigner to y
SSH into the pi and try to `ping 8.8.8.8`. It should fail with no responses.
For full security, put the SD card back in your computer one last time and delete the `ssh` file from `boot`:
```
# mac/Linux:
```bash
# macOS/Linux:
rm ssh
# Windows: