pull down to refresh
I don't dispute the 71 bit puzzle beingbunsolved, but what do you make of this from the block report:
Mk4/Q/Mk5Mk4/Q/Mk5
For a successful reseed with known fallback state and call history:A deliberately loose known-UID ceiling can be obtained by treating every timer field as independent:
- Secure reseed possibilities: at most
2^32- Average enumeration: approximately
2^31
120,000 SysTick values
× 86,400 RTC times
× 256 RTC subsecond values
≈ 2^41.27 fallback statesIncluding the reseed gives a raw ceiling near2^73.27.
This is not 73-bit cryptographic security. The timer fields are correlated, may occupy much smaller ranges, and can potentially be observed or reconstructed.
reply
I had not read the Block report before. But this changes things.
If the entropy is sourced from timers that count from zero at boot, then an attacker is more likely to find a wallet by brute-forcing small timer values.
And also a correlation between SysTick and RTC might bring the effective bits of entropy down.
reply
reply
I think we can use STM32 UIDs to identify legitimate coin owners
That might be hard. Only 32 bits of the UID are used and it's also XORed with SysTick.
pad = UID_low32 ^ SysTick->VAL;In all fairness I did add this clarification after :p
You can check for yourself that Puzzle 71 is uncracked:
https://bitcointalk.org/index.php?topic=5218972.msg53649852#msg53649852
https://mempool.space/address/1PWo3JeB9jrGwfHDNpdGK54CRas7fsVzXU
Source: https://blog.coinkite.com/entropy-technical-backgrounder/