Foundations · 03 / 86 · 3 min
Keys, hashes, and signatures
Three ideas sit under every wallet. You do not need a maths degree. You need to know which one is the secret.
The address can be public. The seed and the private key cannot. A signature is not a harmless click.
A worked case
A site asks for a signature to log in. The message is not a payment, so the person signs. The signature lets a contract move a token they had already approved. The secret was not the password. It was the key.
The key
A private key is the secret that can move the record. A public key is the part other people can see. The address is a shorter name for that public part.
If someone else has the private key, they do not need your password. They have the money.
Hash and signature
A hash is a fingerprint of some data. Change one character and the fingerprint changes. A signature is proof that the holder of the private key approved a specific message.
You will be asked to sign things that are not payments. A signature can still be dangerous. Read what you are signing.
A password with two guesses left
A private key is not a password a company can reset. In January 2021 the New York Times reported on people locked out of bitcoin by their own secrecy. One case was a programmer, Stefan Thomas, who had been paid thousands of bitcoin years earlier and stored the keys in an IronKey device. The device allows a small number of wrong guesses and then encrypts its contents permanently. He had two guesses left. The coins were not gone from the chain. The chain does not care. Without the key, nobody can write the next line.
A hash is the fingerprint that makes that line stick. Change one character in a transaction and the fingerprint changes, so the network rejects it. A signature is the proof that the key approved one particular message. Wallets now ask for signatures to log in, to list a token, or to set an approval. People treat the prompt like a cookie banner. It is closer to a signed letter. If you do not read the letter, you do not know what you approved.
The Times piece is a record of lost keys, not a dare to memorise a seed. The practical lesson is dull: the secret is the seed, the address is the part you may show, and a signature is a decision. No help desk appears in any of those three.
Read it yourself
- New York Times: lost passwords and bitcoin fortunes (2021)
- Bitcoin white paper, on keys and signatures
These links are the record. They are not a recommendation, and they are not instructions. A news story or a court paper can still be wrong about a detail. The check does not change because a famous name is in the story.
Apply the check
Open a question. The line is about this topic. It is not a verdict that anything is safe.
Nobody, until you sign. Then the contract you approved.
The software that builds the message, if you do not read it.
Anyone who has the seed or the private key.
Check yourself
Which part must stay secret?
The private key, and the seed that can rebuild it.
After this you can name the secret (the private key) and refuse to treat a signature as a harmless click.
