Загрузка видео...

Не удалось загрузить видео

На главную

How adding random dice rolls changes the bad initially generated key. Caveats: I’m just punching numbers, not rolling dice. This is not secure. You must have actually rolled dice This only shows that entropy is indeed added. It does not prove the quality of that entropy

15,174 просмотров • 1 месяц назад •via X (Twitter)

Комментарии: 14

Фото профиля Bela Lugosi
Bela Lugosi1 месяц назад

but how can we know that it is not creating a new number from the faulty generator and the rice roll input is just theatre? is there a formula that must be used? possible to verify by zooming the tiny number and calculating that the dice roll input was used in the formula?

Фото профиля The World Mechanic 🌎🧰
The World Mechanic 🌎🧰1 месяц назад

The dice roll feature part of the coldcard can be bypassed entirely. I’ve never used it. You can roll yourself, record each binary input, translate the binary to hex decimal, then to the human readable words. “Import” it to your device, and only use the device to figure out the checksum.

Фото профиля Praveen Perera
Praveen Perera1 месяц назад

raw == prng then sha256(raw) -> sha256(dice_digit) -> sha256(dice_digit)

Фото профиля d4n
d4n1 месяц назад

Oh damn I remember doing this in 2020 clicking random 1-6 numbers and not rolling the dice. I was lucky I had a 2020 mk3 and didn't upgrade the firmware.

Фото профиля Bullcrap
Bullcrap1 месяц назад

The function that feeds the sequence of rolls to generate your private key works fine, it does what it's supposed to, so adding actual dice rolls adds entropy. I'm still ditching my CC.

Фото профиля Carpediem_B
Carpediem_B1 месяц назад

Dug into this with real dice rolls on a Q (fw 1.4.0Q). Confirms what you're seeing: key 4 re-seeds SHA256 with the truncated/full entropy depending on 12 vs 24 words, not a simple concatenation. Built an independent verifier to check it. Thread below 🧵

Фото профиля Simple Steve 🌌
Simple Steve 🌌1 месяц назад

Thank you 🫡

Фото профиля Jay
Jay1 месяц назад

what are the chances of a seed having the same word twice in it? didn’t notice til i was sweeping my funds. fuck

Фото профиля Your Lisbon Guide
Your Lisbon Guide1 месяц назад

Ok, Steve, but if it not broken, don't fix it. There are features that can be used offline with these Mk4 and the Q, so why move away altogether? Don't throw the baby out with the bathwater!

Фото профиля Rumpleskin
Rumpleskin1 месяц назад

This is not how you roll a menmonic. No devices should be in the same room.

Фото профиля Your Lisbon Guide
Your Lisbon Guide1 месяц назад

Of course you have the old pack of cards (even the tarot cards) and the old casino die. Use them!

Фото профиля bad karma
bad karma1 месяц назад

DO NOT FOLLOW THESE INSTRUCTIONS!! Dice rolls is in the Import Existing menu. You should not see 24 words when you start. Please please please delete this 🙏

Фото профиля Sovereign Pleb
Sovereign Pleb1 месяц назад

Randomly punching in numbers works just fine too

Фото профиля SatoshiNagonnaWorkHereAnymoreAnyway
SatoshiNagonnaWorkHereAnymoreAnyway1 месяц назад

For anyone who didn't see this. Nice explainer.

Похожие видео