Seed phrase locking needed on ii2!

The lack of lockable seed phrases on id.ai is a huge security concern. Due to the lack of anchor numbers if someone finds your security key, and holds it near their device, without even knowing the former anchor number they have full access to your II and can reset your seed phrase, locking you out permanently in a few minutes. I understand ii2 is for ease of use but it shouldn’t compromise user security. Also, Legacy II was accessible up until recently from id.ai/legacy , but now returns a canister error.

Can anyone shine light on when lockable seed phrases are coming or what’s going on with the legacy canister for people who still wish to lock theirs.

I support your opinion 100%, I noticed it too, and I am very outraged by it.

see my topic LOCKING of recovery passphrase MUST come back - General - Internet Computer Developer Forum
i post it on before I noticed yours .

Astonishing. I really don’t like IIv2. Not being able to lock seed phrase is bonkers

LOL, I just logged into my OLD (!!!) ii 1.0 (!!!) and LOCKED (!!!) the recovery phrase .

Please restore the old domain, identity.internetcomputer.org, for public use, without redirecting to the new one. I know it still exists under the hood, where the recovery phrase can be locked.

The devs in charge of Internet Identity already confirmed that it’s in the works so unfortunately there’s nothing to do in this case but wait for it to be implemented

https://forum.dfinity.org/t/locking-of-recovery-passphrase-must-come-back/65465/3?u=casualchess

Have you finally figured this out, damn it?

would be nice to have this feature to protect my investments that are down 95%

Bumping this thread—how is the work coming along? I see you’re really hard at work on this incredibly complex problem!!

setting up a recovery phrase is supported for quite a while already, see https://forum.dfinity.org/t/recovery-phrases-are-now-available-on-id-ai/61763

I’m encountering a bug/error/problem. I’ve been trying to recover my II using my original recovery phrase (which I locked for security reasons), but now after II2.0, I can’t recover it. I tried this with two IIs that I set up on December 2024, none of them can be recovered using the 24 words recovery key.

One of my IIs is accessible on my phone, so I can operate with it. But the other one isn’t accessible. That’s why I was trying to recover it. After failing, I did a test with the other one, and none worked.

Is there a problem that unbinds the recovery keys from their respective II account after ver 2.0?

did you test the route with the legacy identity for recovery (3rd button) or did you try with the first button?

When can we lock II seed phrase? I recently tried to and realized there s no more such option

People should be able to add multiple recovery devices and burn their recovery phrase if they wish so(or not)

if someone steals ur recovery phrase - it’s game over(if u burn it and lock, theres nothing to steal)

if someone gets a temporary access to one of your auth keys - it’s game over(they can change recovery phrase and lock u out completely), if phrase is locked they cannot do anything and ur account always stays with u(attacker can unbind all ur keys but if u control the phrase u can take it back)

I thought ICP put special focus on security, but after recent changes it seems no longer the case
If you concerned about misuse - hide this in ‘for advanced users’ section and put huge disclaimer in red

but it must be here for those who wants extra protection and knows what he is doing

I tried both. The third option doesn’t work for my case, because my legacy passkey is wiped off my iPhone. Then tried the recovery key option. But it says the key is wrong, then tried with another II account, the same result. Today I’ll try another account to see if it recovers

This feature has been removed due to an inherent problem: If a user loses their recovery phrase but still have access (e.g., using passkeys), they cannot reset a locked recovery phrase.

Previously locked recovery phrases can be unlocked in id.ai.

Users can add multiple passkeys that are stored on, e.g., YubiKeys, and store those securely as a recovery device. II doesn’t distinguish recovery passkeys from regular passkeys as they are technically the same, but users can add custom labels to remember the role of a particular passkey.

if someone steals ur recovery phrase - it’s game over(if u burn it and lock, theres nothing to steal)

Recovery phrases are not for everyone. Some users want this, others do not.

That’s why it’s up to the user to set up a recovery phrase. Resetting your recovery phrase and not writing it down is practically equivalent to removing it.

Even if II would somehow protect the user in this scenario, the attacker could drain liquid assets controlled by that identity before the user would have time to react.

That’s why we currently focus on preventative measures, like requiring two-factor-enabled hardware passkey managers (e.g., YubiKeys must have PIN enabled, preventing whoever finds them from automatically gaining access).

I just tried and successfully recovered using a recovery phrase on https://id.ai/recovery

Please double check that your phrase is from the right product. Sometimes it’s easy to confuse, e.g., a seed phrase from a ledger device with a recovery phrase from II.

If you are sure you got the right phrase, please attach screenshots or a video recording of what you see on the screen, so we can provide the best assistance.

It’s practically equivalent but it’s not the same, there’s a moment where u have it exposed(u can be spied on, ur device can be stealth-compromised, etc)
Why cannot we have an opt-in option to permanently burn recovery phrase in a totally secure way?

Aka if user wants to forfeit his right to ever use a recovery phrase and he understands what it means
Or at least a way to forfeit this right for some time(6 month, a year).

I would feel a lot safer if I could lock out recovery phrase for a year and allow only 3 authorized keys which are pin-protected(or they could even be pin+sd card+trezor protected, trezor can do the same stuff yubikey can)