Warren
Community forum

How forum sign-in protects you

The Warren forum has no emails, no passwords, and never sees your IP address. You sign in by proving control of your Warren wallet key: the app signs a one-time challenge with Ed25519. Nothing to remember, nothing to leak.


What each party can see

PartySees
The forum (Discourse)your opaque handle (e.g. lusab-babad-dovok), a synthetic non-routable .invalid email, the constant address 0.0.0.0 instead of your IP, and your posts
Anyone reading the forumyour handle and posts. The handle is derived with a keyed HMAC: it cannot be reversed or correlated with a Warren account address
Warren (this sign-in service)your wallet public key at login time, for as long as it takes to verify your signature. What is kept afterwards is a keyed hash (HMAC) of that address, next to your handle. Support can find your handle from an address you give them; the reverse is impossible

Stored at rest: one row per account, holding that keyed hash, your handle, and the dates of your first and last sign-in. Your wallet address is not in it. A row with no sign-in for two years is deleted automatically.

IP masking, verbatim edge configuration

The reverse proxy in front of the forum pins the forwarded address headers to a constant before any request reaches Discourse:

reverse_proxy discourse:80 {
    header_up X-Forwarded-For "0.0.0.0"
    header_up X-Real-IP "0.0.0.0"
}

Discourse therefore stores 0.0.0.0 as every user's IP, including at account creation (verified end to end). Access logs are disabled on the forum vhost.

What we deliberately cannot do


A burrow, not footprints.