BIP-39 paper key suggested when creating a profile

Believe it or not, quite a lot of people still use plain paper to backup their account passwords.

Current problem of Delta Chat is that you always need a digital backup of your key to restore your account. Worse: when you create your account, there’s little incentive to do a backup which has to be transfered to another device.

My suggestion is, when creating a new account/new profile, to display the private key using BIP-39 words (multiple languages are supported). User should be encouraged to save this BIP-39 words list on a secure device (either a file or on paper).

Wording could include:

“Delta Chat doesn’t use a password but a private key stored on your linked devices. If you lost access on your linked devices, the followling words list is the only way to recover your account. But anyone having access to this list could take over your account. So write it down and keep it in a safe place.”

there is a type mismatch here:

there is no such thing as an “account you create with Delta Chat”.

you create a “profile”, which exist on your devices and backups only. for delivering messages, community-run “chat relays” with random addresses are used. they do not store anything that could be used for recovering, you are not even tied to a particular relay.

if you lost access to all your devices and backup files, there is nothing stored somewhere magically, password or not:

all this is by design, in contrast to most other messengers, there are no severs that hold permanent data.

that being said, we are thinking sometimes about encouraging ppl more to set up a second device or do a backup, e.g. after some days of using the app

For most people, it would still be “an account”. Also, if you read my proposal carefully, you will see that I’m fully aware of that (hence using the word account/profile)

i re-read the proposal, but i do not get how it should work, to recover by just a passphrase. please elaborate

the BIP-39 should contain the key itself?

without looking closely, i fear, there are not enough bits available for storing they practically key there. let alone contacts, groups, message history

BIP-39 is a “standard” which converts cryptographic keys into words list. It is quite straightforward and, yes, there are enough bits (it is used by most Bitcoin wallets and Protonmail recovery.)

k, now i got it. BIP-39 with max. 256 bits resp. 32 bytes is enough for a Ed25519 key.

while Ed25519 is the current standard key for Delta Chat, we were using other formats in the past, and also in the future, wrt post quantum. so it is clear today, that BIP-39 is not sufficient. one need to use multiple of then, resulting in writing down more than 100 words.

and: as mentioned, if you have a profile with contacts etc., restoring the key is by far not a backup. you would not be able to contact anyone (as you lost all relay information of the contacts) nor someone could contact you (as they do not have your new relay information)

for e.g. protonmail, this is different, as there is probably an “account” holding contacts etc.

but yes, interesting to think about

But if you restore the key, people will be able to contact you and then, it would slowly restore your contact list, am I right?

the proposal is basically about “export my private key” we used to have options to export the private key as .asc file in the past, this proposal is about bringing that back but making that process more user-friendly by exporting as a memorable passphrase,

this is quite common/practical way to store your private key in crypto-currency apps, a more closer case is Session messenger, where you can recover your account/profile using such “recovery phrase”

For Delta Chat it technically makes some sense as well since the key is your one and only identity and “account”, but groups, chats, contacts, messages, etc. will be lost, more importantly: your relays will be lost, so you will not just start receiving messages from that point on, you will need to reestablish contact with everyone and join groups and channels again anyways, so while you keep the same identity/id/dc-account/profile it is mostly the same as starting with a fresh profile

overall I am not sure it is worth adding, it is kind of an advance feature, and might give the wrong impression to people that they can just wipe the app or log in in a new device just with the passphrase and end up with two devices with completely different state and relays, at the end it is basically about the same result as starting over with a new profile, so the current approach just providing second device / backup as way to keep your account is a clearer story

no, because people need 2 things to contact you: your public key (a.k.a your Delta Chat user ID, your cryptographic identity) and then your relays, the underlying email accounts/inboxes where they are sending messages to, if you backup only the private key and then restore it in a new profile with new email addresses, so you will not be receiving any of the messages people are still trying to send to the old email inboxes, at the end you need to scan QRs etc again as when starting from scratch

that is: there are 2 levels of accounts/profile:

  1. your abstract “delta chat profile” that is your cryptographic identity, used for encrypting/decrypting messages
  2. your underlying email accounts a.k.a “relays”, used for sending/receiving

just backing up one of them doesn’t allow you to restore your profile/account properly, you need both

Thanks for clarifying. Not having read the doc, I thought that multi-account support was made possible through some kind of autodiscovery (asking servers: “do you have an account with that key?”)

But if account should be saved, saving the key only is indeed not really useful.

I see two potential mitigations:

  1. Adding the smtp account info in the “recovery key”
  2. Implementing some sort of autodiscovery like described above.

But, yeah, this is hard and long term work, not something that could be easily plugged-in like a BIP-39 pgp key export

Your client can choose the password for a chatmail server account arbitrarily. You would need one less thing to remember if it was generated deterministically using a password derivation function (hash) based on the private key and the hostname.

Querying the email address corresponding to a public key fingerprint is already possible using public key servers - you could submit yours to one already:
https://en.wikipedia.org/wiki/Key_server_(cryptographic)#Keyserver_examples

Yes, it would be ideal if such a backup contained everything but message content that could easily compress to a manageable size:

It can then be printed on a single sheet of paper:

There are two different aspects of the backup here:

  1. Recovering access to your account and your contacts.
  2. Recovering all your chat history.

I believe that 2. is more optional. If something is critical, you will save it in other place. And even non-tech people can understand that they lost their history if no backup was done or if you lost all your devices. While losing access to your accounts is way more annoying.