nsnjx's avatar
nsnjx 2 months ago
I see, but in that case it still depends on a special email service. My project is Chuchu, and I plan to add third-party logins. My idea is to derive a unique private key from: 1)the unique secret obtained from third-party login, and 2)a user-provided passcode, so that no dedicated server is needed.

Replies (2)

So the user has to remember their passcode still? Is there a way to recover the secret from storage if they lose it? How do they sign things, is their encrypted key returned to the client to sign with? I'm interested in the details.