Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

How adding random dice rolls changes the bad initially generated key. Caveats: I’m just punching numbers, not rolling dice. This is not secure. You must have actually rolled dice This only shows that entropy is indeed added. It does not prove the quality of that entropy

15,174 görüntüleme • 1 ay önce •via X (Twitter)

14 Yorum

Bela Lugosi profil fotoğrafı
Bela Lugosi1 ay önce

but how can we know that it is not creating a new number from the faulty generator and the rice roll input is just theatre? is there a formula that must be used? possible to verify by zooming the tiny number and calculating that the dice roll input was used in the formula?

The World Mechanic 🌎🧰 profil fotoğrafı
The World Mechanic 🌎🧰1 ay önce

The dice roll feature part of the coldcard can be bypassed entirely. I’ve never used it. You can roll yourself, record each binary input, translate the binary to hex decimal, then to the human readable words. “Import” it to your device, and only use the device to figure out the checksum.

Praveen Perera profil fotoğrafı
Praveen Perera1 ay önce

raw == prng then sha256(raw) -> sha256(dice_digit) -> sha256(dice_digit)

d4n profil fotoğrafı
d4n1 ay önce

Oh damn I remember doing this in 2020 clicking random 1-6 numbers and not rolling the dice. I was lucky I had a 2020 mk3 and didn't upgrade the firmware.

Bullcrap profil fotoğrafı
Bullcrap1 ay önce

The function that feeds the sequence of rolls to generate your private key works fine, it does what it's supposed to, so adding actual dice rolls adds entropy. I'm still ditching my CC.

Carpediem_B profil fotoğrafı
Carpediem_B1 ay önce

Dug into this with real dice rolls on a Q (fw 1.4.0Q). Confirms what you're seeing: key 4 re-seeds SHA256 with the truncated/full entropy depending on 12 vs 24 words, not a simple concatenation. Built an independent verifier to check it. Thread below 🧵

Simple Steve 🌌 profil fotoğrafı
Simple Steve 🌌1 ay önce

Thank you 🫡

Jay profil fotoğrafı
Jay1 ay önce

what are the chances of a seed having the same word twice in it? didn’t notice til i was sweeping my funds. fuck

Your Lisbon Guide profil fotoğrafı
Your Lisbon Guide1 ay önce

Ok, Steve, but if it not broken, don't fix it. There are features that can be used offline with these Mk4 and the Q, so why move away altogether? Don't throw the baby out with the bathwater!

Rumpleskin profil fotoğrafı
Rumpleskin1 ay önce

This is not how you roll a menmonic. No devices should be in the same room.

Your Lisbon Guide profil fotoğrafı
Your Lisbon Guide1 ay önce

Of course you have the old pack of cards (even the tarot cards) and the old casino die. Use them!

bad karma profil fotoğrafı
bad karma1 ay önce

DO NOT FOLLOW THESE INSTRUCTIONS!! Dice rolls is in the Import Existing menu. You should not see 24 words when you start. Please please please delete this 🙏

Sovereign Pleb profil fotoğrafı
Sovereign Pleb1 ay önce

Randomly punching in numbers works just fine too

SatoshiNagonnaWorkHereAnymoreAnyway profil fotoğrafı
SatoshiNagonnaWorkHereAnymoreAnyway1 ay önce

For anyone who didn't see this. Nice explainer.

Benzer Videolar