pull down to refresh

I had not read the Block report before. But this changes things.

If the entropy is sourced from timers that count from zero at boot, then an attacker is more likely to find a wallet by brute-forcing small timer values.

And also a correlation between SysTick and RTC might bring the effective bits of entropy down.

This may also be helpful:

source

reply
I think we can use STM32 UIDs to identify legitimate coin owners

That might be hard. Only 32 bits of the UID are used and it's also XORed with SysTick.

pad = UID_low32 ^ SysTick->VAL;
reply

This is the best info I've seen so far:

From around 1200 UTC.

The researchers at block still haven't published any updates since their original blog post.

reply