thunderbiscuit / thunderbiscuit/bdk-requested-features

Encryption at rest of the wallet's persistence

Open
#4 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
1
Forks
0
PR merge metrics
No merged PRs in 30d

Description

Our default production persistence for bdk_wallet is a SQLite database file, which doesn't come with out-of-the-box encryption at rest. And while the data contained in the db doesn't contain any private key material, keeping this data in plaintext is a privacy-level issue users in production would love to mitigate, particularly as we are hoping to ship #3.

Known users/projects who have requested this or are rolling out their own

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining bdk_wallet's default SQLite persistence and the production use case described here, then review how this relates to issue #3. Define an encryption-at-rest approach and acceptance criteria for protecting the database file without exposing private key material; the payload names no files or tests to run.

Written by the indexing model from the issue text.

Assessment

Tech stack
sqlite
Domain
databases, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.