Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your passkey can be an encryption address. The domain is the key.

There is still no simple way to encrypt something to a person. You can encrypt to a server, or to someone you have already swapped keys with, but not to "Maya, whoever and wherever she is." I built Letterlock to try: the passkey you already have becomes an encryption address . Your device derives an X25519 key from the passkey, publishes only the public half to a directory contract on Monad, and…

Your passkey can function as both an encryption address and an encryption key. This is achieved by deriving an X25519 key from the passkey, publishing the public half to a directory contract on Monad, and allowing any app or agent to look up the key with a single read. The derivation process involves using WebAuthn's PRF extension to generate a 32-byte secret, which is then converted into an X25519 private key through HKDF.

The salt used for this process is unique to the passkey and not shared with any other credential. The domain to which the passkey is bound is essentially the encryption key, as it shapes the design and functionality of the system.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 3 October →