Skip to content

Commit ba3f00a

Browse files
committed
docs: Clarify offline recovery preparation
Require the signer to have the chain history needed for a rescan before it is air-gapped, and avoid a redundant standalone card check before ms32 wallet performs recovery validation. Refs #93.
1 parent 1dcee71 commit ba3f00a

1 file changed

Lines changed: 11 additions & 11 deletions

File tree

‎docs/user/guide.md‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -200,9 +200,10 @@ worth the extra steps.
200200
## More protection: watch-only wallet and offline signer
201201

202202
On the offline signer, create an empty encrypted descriptor wallet with private
203-
keys enabled and run `ms32 wallet`. Keep that computer permanently disconnected
204-
from every network as soon as Bitcoin Core and codex32 are installed and
205-
disconnect before recovery text or signing keys are present.
203+
keys enabled and run `ms32 wallet`. If this signer may need to rescan an
204+
existing wallet, synchronize Bitcoin Core or copy in the required chain history
205+
before making the signer permanently offline. Then disconnect every network
206+
path before entering recovery text or exposing signing keys.
206207

207208
After the signer is restored, follow Bitcoin Core's maintained
208209
[offline-signing tutorial](https://github.com/bitcoin/bitcoin/blob/master/doc/offline-signing-tutorial.md).
@@ -224,12 +225,11 @@ its public wallet data with the separate wallet record.
224225
1. Collect the required cards with matching identifiers and text lengths.
225226
2. Find the separately stored wallet record and the original wallet
226227
instructions.
227-
3. On Tails or another reviewed offline computer, check each card with
228-
`ms32 check`. If validation fails, recheck what you typed before assuming
229-
the paper is wrong.
230-
4. Disable Ethernet, internet, Tor, Wi-Fi, Bluetooth, cellular, and every other
231-
network path. Load a blank encrypted descriptor wallet with private keys
232-
enabled in Bitcoin Core, and run:
228+
3. Before entering recovery text, ensure the offline signer already has the
229+
Bitcoin Core chain history needed for the requested rescan. Then disable
230+
Ethernet, internet, Tor, Wi-Fi, Bluetooth, cellular, and every other network
231+
path. Load a blank encrypted descriptor wallet with private keys enabled in
232+
Bitcoin Core, and run:
233233

234234
```bash
235235
ms32 wallet --timestamp 0
@@ -238,11 +238,11 @@ its public wallet data with the separate wallet record.
238238
If you know when the wallet was first used, an earlier Unix timestamp can
239239
shorten the rescan; `0` remains the safest choice when unsure.
240240

241-
5. Select and confirm that wallet. If it is locked, follow the displayed
241+
4. Select and confirm that wallet. If it is locked, follow the displayed
242242
Bitcoin-Qt Console instructions; codex32 waits and continues automatically.
243243
It gives Core the master private key, asks Core to create the standard
244244
account-0 descriptors, scans history, and relocks an encrypted wallet.
245-
6. If you need an online watch-only counterpart, keep the restored signer
245+
5. If you need an online watch-only counterpart, keep the restored signer
246246
offline and follow Bitcoin Core's
247247
[offline-signing tutorial](https://github.com/bitcoin/bitcoin/blob/master/doc/offline-signing-tutorial.md)
248248
to export and restore the watch-only wallet. Let the online node synchronize,

0 commit comments

Comments
 (0)