Tag: web3 security

  • Day 15 — What Actually Makes an App a dApp?

    Watercolor illustration of a user interface connecting a wallet to decentralized smart contracts

    A decentralised application, or dApp, can look just like any other website. It may have buttons, forms, charts, and a familiar login screen. The difference is not mainly visual; it lies in where the important rules and records live.

    A typical dApp has three layers. The frontend is the website or mobile interface. A wallet connects the user’s account and signs instructions. Smart contracts on a blockchain hold the shared state and enforce the core rules. The interface might say Swap, but the contract determines what assets move and under which conditions.

    Reading from a dApp can be almost invisible. The website asks a node for contract data and displays balances or prices. Writing is different: changing blockchain state requires a transaction. Your wallet shows what is being requested, you sign it, the network executes it, and gas is paid even if the transaction later fails.

    Decentralisation is not an all-or-nothing label. A contract may be immutable while its website is hosted by one company. Its data may depend on a centralised server, or an administrator may retain an upgrade key. A useful evaluation asks which parts can be censored, changed, or switched off—and by whom.

    Wallet-based access removes the need to create a new username and password for every service, but it changes the security model. A signature can authorise a harmless login, a token approval, or a valuable transfer. Users must understand the request because there may be no support desk capable of reversing a mistaken signature.

    Good dApps make these boundaries clear: they show contract addresses, transaction details, risks, and the source of external data. Open contracts can be inspected and reused, but open code does not mean bug-free code. Audits help; they never turn software into a guarantee.

    One puzzle remains. A smart contract can read blockchain data, but how can a lending app learn the rupee price of ether or whether it rained in Delhi? Tomorrow we meet the bridge called an oracle.

  • Day 11 — How Can a Wallet Prove It Is You Without a Password?

    A private wallet key creating a verifiable digital signature

    A crypto wallet looks a little like a banking application, but the similarity can be misleading. The wallet does not contain coins, and a blockchain does not keep a private password database for its users. What the wallet protects is a cryptographic secret that allows its owner to authorise changes on the public ledger.

    This secret is called a private key. From it, software can derive a public key and an address that other people may safely know. When you send ether or interact with a smart contract, the wallet uses the private key to create a digital signature. The private key itself does not leave the wallet. The signature travels with the transaction.

    A digital signature acts like a seal tied both to the signer and to the exact message being signed. Ethereum nodes can use public information to verify that the signature could only have been produced by the corresponding private key. If even one detail of the transaction changes, the old signature will no longer match.

    This gives the network proof without requiring identity. Ethereum does not need to know your name, email address or face. It needs to know that the holder of a particular key approved a particular instruction. Control of the key therefore becomes control of the account, which is why ‘not your keys, not your coins’ is more than a slogan.

    Wallets often represent the key through a recovery phrase made from a list of words. That phrase can recreate the wallet’s keys, so anyone who obtains it may gain the same control as the owner. There is usually no central help desk capable of reversing the theft. A wallet interface can be replaced; a compromised recovery phrase cannot be made secret again.

    Signatures remove the need to share passwords with every application, but they create a new responsibility: understanding what is being signed. A malicious website may ask for approval that looks harmless while granting broad control over tokens. Good wallet security includes reading transaction details, limiting approvals and keeping recovery information offline.

    Now we can prove who authorised a transaction. But what exactly does an Ethereum account own? Bitcoin speaks about individual unspent outputs, while Ethereum often shows a simple balance. The two systems organise ownership in very different ways.