Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

How adding random dice rolls changes the bad initially generated key. Caveats: I’m just punching numbers, not rolling dice. This is not secure. You must have actually rolled dice This only shows that entropy is indeed added. It does not prove the quality of that entropy

15,174 Aufrufe • vor 1 Monat •via X (Twitter)

14 Kommentare

Profilbild von Bela Lugosi
Bela Lugosivor 1 Monat

but how can we know that it is not creating a new number from the faulty generator and the rice roll input is just theatre? is there a formula that must be used? possible to verify by zooming the tiny number and calculating that the dice roll input was used in the formula?

Profilbild von The World Mechanic 🌎🧰
The World Mechanic 🌎🧰vor 1 Monat

The dice roll feature part of the coldcard can be bypassed entirely. I’ve never used it. You can roll yourself, record each binary input, translate the binary to hex decimal, then to the human readable words. “Import” it to your device, and only use the device to figure out the checksum.

Profilbild von Praveen Perera
Praveen Pereravor 1 Monat

raw == prng then sha256(raw) -> sha256(dice_digit) -> sha256(dice_digit)

Profilbild von d4n
d4nvor 1 Monat

Oh damn I remember doing this in 2020 clicking random 1-6 numbers and not rolling the dice. I was lucky I had a 2020 mk3 and didn't upgrade the firmware.

Profilbild von Bullcrap
Bullcrapvor 1 Monat

The function that feeds the sequence of rolls to generate your private key works fine, it does what it's supposed to, so adding actual dice rolls adds entropy. I'm still ditching my CC.

Profilbild von Carpediem_B
Carpediem_Bvor 1 Monat

Dug into this with real dice rolls on a Q (fw 1.4.0Q). Confirms what you're seeing: key 4 re-seeds SHA256 with the truncated/full entropy depending on 12 vs 24 words, not a simple concatenation. Built an independent verifier to check it. Thread below 🧵

Profilbild von Simple Steve 🌌
Simple Steve 🌌vor 1 Monat

Thank you 🫡

Profilbild von Jay
Jayvor 1 Monat

what are the chances of a seed having the same word twice in it? didn’t notice til i was sweeping my funds. fuck

Profilbild von Your Lisbon Guide
Your Lisbon Guidevor 1 Monat

Ok, Steve, but if it not broken, don't fix it. There are features that can be used offline with these Mk4 and the Q, so why move away altogether? Don't throw the baby out with the bathwater!

Profilbild von Rumpleskin
Rumpleskinvor 1 Monat

This is not how you roll a menmonic. No devices should be in the same room.

Profilbild von Your Lisbon Guide
Your Lisbon Guidevor 1 Monat

Of course you have the old pack of cards (even the tarot cards) and the old casino die. Use them!

Profilbild von bad karma
bad karmavor 1 Monat

DO NOT FOLLOW THESE INSTRUCTIONS!! Dice rolls is in the Import Existing menu. You should not see 24 words when you start. Please please please delete this 🙏

Profilbild von Sovereign Pleb
Sovereign Plebvor 1 Monat

Randomly punching in numbers works just fine too

Profilbild von SatoshiNagonnaWorkHereAnymoreAnyway
SatoshiNagonnaWorkHereAnymoreAnywayvor 1 Monat

For anyone who didn't see this. Nice explainer.

Ähnliche Videos