Hardware wallets typically do not show balances. If they did, how would you know that they have the correct chain?
Of course any particular software wallet can’t be trusted (to the same extent as you typically trust the hardware wallet) to show the correct balance. It could show anything. That’s the point of a hardware wallet: to separate the authority needed to transfer funds from the authority needed to view balances. It’s indeed a vulnerability that you don’t have a trusted path to show you a reliable balance. C’est la vie.
The problem is that if you reveal a seed phrase, you’ve amplified what would normally be an attack on the integrity of balance information, to an attack that can steal funds that were held under that seed phrase.
My point is that the wallet that you didn’t reveal the seed phrase of, could be trusted (at least I do). However, if you do not trust any software wallet then I understand your concern.
I hope we can figure something out for the next poll, I did not vote in this because the process is just out of control IMO. But it is awesome that people can vote, I just hope there’s a better way in the future.
I did not try, moving funds was a deal breaker for me. I would prefer just signing a msg. I keep a material portion of my net worth in zec and just did not think it was worth the concern of moving everything back and forth. I feel like sharing a seed phrase is anti crypto and I have never done it and never will. To be fair though, it doesn’t matter, what is a material portion of my net worth is surely nothing compared to any significant voter. I look forward to seeing the results and potentially voting in the future if the mechanism changes! <3
Could you please clarify this temporary results? I don’t know if the election 1 is the question chosen as first to implement or something else. For me it’s clear what the ballots counter mean but not so clear the election position. Thanks in advance.
The 11 questions were selected by the folks organizing the election. I am part of the Vote Authorities who operationally run the election but who are seperate from folks who created the election.
The way the current version works is a vote.db is created with the 11 questions and shared with everyone running the zcash-vote-server + cometbft software combo. The issue is the order of those questions, once input, changes when we setup. So that is why the question numbers do not map to the same election id.
Why would you have any more reason to trust one software wallet than another? There’s no rational basis for that, especially if they are the same wallet implementation, as they usually will be for this protocol. (Why would you choose a wallet implementation that you trust or run it on a platform that you trust for one of { the temporary account used for this protocol, your long-term account }, and not also do so for the other?)
I already described the trust requirements needed to be able to ensure the funds are not stolen in my original comment describing the attack. None of your subsequent comments have been in any way valid objections to that attack — I just want to make that crystal clear to anyone reading this thread. Please also read my post about other risks associated with this protocol and its reliance on making large funds transfers just to support voting.
One of the wallet implementation is Zashi running the Keystone h/w. This one is connected to the original wallet, the seed phrase is not used in the coin voting and it is running on a different hardware. I trust that one.
Anyway, obviously you do what you feel comfortable with.
Well, considering that you do not trust the above mentioned wallet, then yeah I suppose so.
It’s irrelevant that this is using a Keystone. You can’t see the balance on the Keystone; you are entirely trusting software (and the platform it runs on) to show you the balance.
It’s irrelevant that the seed phrase for this wallet is not used in the coin voting. You are trusting the software of this wallet to verify that funds have left the wallet for which you are revealing the seed phrase.
The fact that you’ve mentioned irrelevant things as being reasons why you trust this wallet is what makes me concerned that you still don’t understand the risk of this attack, and how it could affect other users.
In particular, anyone who needs the security of a hardware wallet should not use this protocol.
That’s correct. I trust the wallet the software to show me the balance for an account that was not used in coin voting. I simply used Zashi + Keystone as an example though I personally don’t use these (I use my own wallet software).