Loading video...

Video Failed to Load

Go Home

How adding random dice rolls changes the bad initially generated key. Caveats: I’m just punching numbers, not rolling dice. This is not secure. You must have actually rolled dice This only shows that entropy is indeed added. It does not prove the quality of that entropy

15,174 views • 1 month ago •via X (Twitter)

14 Comments

Bela Lugosi's profile picture
Bela Lugosi1 month ago

but how can we know that it is not creating a new number from the faulty generator and the rice roll input is just theatre? is there a formula that must be used? possible to verify by zooming the tiny number and calculating that the dice roll input was used in the formula?

The World Mechanic 🌎🧰's profile picture
The World Mechanic 🌎🧰1 month ago

The dice roll feature part of the coldcard can be bypassed entirely. I’ve never used it. You can roll yourself, record each binary input, translate the binary to hex decimal, then to the human readable words. “Import” it to your device, and only use the device to figure out the checksum.

Praveen Perera's profile picture
Praveen Perera1 month ago

raw == prng then sha256(raw) -> sha256(dice_digit) -> sha256(dice_digit)

d4n's profile picture
d4n1 month ago

Oh damn I remember doing this in 2020 clicking random 1-6 numbers and not rolling the dice. I was lucky I had a 2020 mk3 and didn't upgrade the firmware.

Bullcrap's profile picture
Bullcrap1 month ago

The function that feeds the sequence of rolls to generate your private key works fine, it does what it's supposed to, so adding actual dice rolls adds entropy. I'm still ditching my CC.

Carpediem_B's profile picture
Carpediem_B1 month ago

Dug into this with real dice rolls on a Q (fw 1.4.0Q). Confirms what you're seeing: key 4 re-seeds SHA256 with the truncated/full entropy depending on 12 vs 24 words, not a simple concatenation. Built an independent verifier to check it. Thread below 🧵

Simple Steve 🌌's profile picture
Simple Steve 🌌1 month ago

Thank you 🫡

Jay's profile picture
Jay1 month ago

what are the chances of a seed having the same word twice in it? didn’t notice til i was sweeping my funds. fuck

Your Lisbon Guide's profile picture
Your Lisbon Guide1 month ago

Ok, Steve, but if it not broken, don't fix it. There are features that can be used offline with these Mk4 and the Q, so why move away altogether? Don't throw the baby out with the bathwater!

Rumpleskin's profile picture
Rumpleskin1 month ago

This is not how you roll a menmonic. No devices should be in the same room.

Your Lisbon Guide's profile picture
Your Lisbon Guide1 month ago

Of course you have the old pack of cards (even the tarot cards) and the old casino die. Use them!

bad karma's profile picture
bad karma1 month ago

DO NOT FOLLOW THESE INSTRUCTIONS!! Dice rolls is in the Import Existing menu. You should not see 24 words when you start. Please please please delete this 🙏

Sovereign Pleb's profile picture
Sovereign Pleb1 month ago

Randomly punching in numbers works just fine too

SatoshiNagonnaWorkHereAnymoreAnyway's profile picture
SatoshiNagonnaWorkHereAnymoreAnyway1 month ago

For anyone who didn't see this. Nice explainer.

Related Videos