ms32 share INDEX derives one share per run, so adding three cards means entering the existing cards three times.
ms32 share should accept several indices, for example ms32 share cdf. The operator enters the existing cards once, then writes and re-enters each new card.
- The operator must name the indices.
share gets no option for a random count: other cards from the set already exist, so a random index among the 31 could recreate one of them.
- A repeated index makes another copy of that share. This applies to
share and to create --indices, which currently rejects repeats with "output indices must be distinct".
- Repeats move to the end of the order, so the same share is never confirmed twice in a row. For example,
aacd runs a, c, d, a.
share also accepts the index of a card that was entered and makes a copy of that card. If every requested index matches an entered card, those cards are all it needs. A threshold of cards is needed only when at least one requested index is new. This replaces today's "INDEX must differ from S and the input indices" rule.
S is still rejected. ms32 secret shows the secret, and create is where a secret card gets confirmed.
Security note: in create, the first threshold cards are random and the rest are derived. A repeated index among the random cards would produce two different shares with the same index. So repeats must come after the random cards and be copies of the card already confirmed, and the minimum-count check must count distinct indices. This changes share generation, so it needs a security review before it is marked ready.
ms32 share INDEXderives one share per run, so adding three cards means entering the existing cards three times.ms32 shareshould accept several indices, for examplems32 share cdf. The operator enters the existing cards once, then writes and re-enters each new card.sharegets no option for a random count: other cards from the set already exist, so a random index among the 31 could recreate one of them.shareand tocreate --indices, which currently rejects repeats with "output indices must be distinct".aacdruns a, c, d, a.sharealso accepts the index of a card that was entered and makes a copy of that card. If every requested index matches an entered card, those cards are all it needs. A threshold of cards is needed only when at least one requested index is new. This replaces today's "INDEX must differ from S and the input indices" rule.Sis still rejected.ms32 secretshows the secret, andcreateis where a secret card gets confirmed.Security note: in
create, the firstthresholdcards are random and the rest are derived. A repeated index among the random cards would produce two different shares with the same index. So repeats must come after the random cards and be copies of the card already confirmed, and the minimum-count check must count distinct indices. This changes share generation, so it needs a security review before it is marked ready.