Wallets · 25 / 127 · 1 min
Blind signing
The device can keep the key offline and still show you nothing but a hash. You are confirming a fingerprint.
The key stayed offline. The message was still whatever you confirmed.
A worked case
A device shows a string of hex. The owner confirms because the device has never failed them. The computer had been aimed at a bad page. The device did its job. The job was not to understand the page.
What the screen owes you
A hardware wallet that shows the amount and the address is showing the payment. A screen that shows a hash is showing that some message exists.
The habit
People confirm the hash because the device feels safe. The device signed what the computer asked. Safety was the key staying off the computer, not the message being honest.
The device showed a hash
A hardware wallet keeps the private key off the computer you browse with. It still signs the message the computer hands it, once you confirm. If the screen shows a hash rather than the amount and the destination, you confirmed a fingerprint.
The device did not fail. The confirmation was the decision. A fingerprint of a bad message is still the bad message.
Read it yourself
These links are the record. They are not a recommendation, and they are not instructions. A news story or a court paper can still be wrong about a detail. The check does not change because a famous name is in the story.
Apply the check
Open a question. The line is about this topic. It is not a verdict that anything is safe.
Whoever the signed message pays.
You, at the confirmation. The device does not know the payee.
The signature.
Check yourself
Write it in your own words. The course's answer opens after that. Nothing is sent.
After this you can refuse a hash you cannot read when the payment matters.
